CVE-2025-32434PoC(linuxfoundation / pytorch)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation pytorch systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pytorch

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
pytorch

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-20: 103-2003-24
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-201
PoC1
2026-03-241
General1
Full discourse2 posts
  • 電話莎( ˘・з・)@一半是vtuber一半是社畜@telephone_sa
    General

    2. 安裝的 torch 版本太舊 自動安裝的是 torch 2.5.1+cu121,但 transformers 因為 CVE-2025-32434 漏洞要求至少 v2.6,直接噴 ValueError

    Post summary

    The text notes that transformers require torch v2.6+ because of CVE‑2025‑32434, but provides no PoC, exploit code, or detailed technical information.

    10000129
    27 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #PyTorch: disponibile #PoC per lo sfruttamento della CVE-2025-32434 Rischio: 🟠 Tipologia: 🔸Remote Code Execution 🔗 https://www.acn.gov.it/portale/w/pytorch-disponibile-poc-per-lo-sfruttamento-della-cve-2025-32434 ⚠ Importante aggiornare i software interessati https://t.co/bmUbyAArsK

    Post summary

    The tweet announces a PoC for CVE‑2025‑32434 in PyTorch, identifies it as a remote code execution vulnerability, and urges users to update software.

    00000117
    608 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationpytorch-python-

Explore more