CVE-2025-3677
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 16, 2025
CWE ID 502
CWE ID 20
Summary
CVE-2025-3677 is a critical deserialization vulnerability discovered in the lm-sys fastchat software version 0.2.36. Specifically, the issue lies within the function "split_files/apply_delta_low_cpu_mem" of the file "fastchat/model/apply_ delta.py." This vulnerability can be exploited through local manipulation, allowing an attacker to deserialize data and potentially execute arbitrary code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.