CVE-2025-3677

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 16, 2025
CWE ID 502
CWE ID 20

Summary

CVE-2025-3677 is a critical deserialization vulnerability discovered in the lm-sys fastchat software version 0.2.36. Specifically, the issue lies within the function "split_files/apply_delta_low_cpu_mem" of the file "fastchat/model/apply_ delta.py." This vulnerability can be exploited through local manipulation, allowing an attacker to deserialize data and potentially execute arbitrary code.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share