CNNVD-202508-938 Information

CNNVD ID

CNNVD-202508-938

CVE-2025-45146

  • CNNVD Published: 2025-08-11

Description (Chinese)

ModelCache是codefuse-ai开源的一个LLM语义缓存系统,旨在通过缓存查询结果对减少响应时间来增强用户体验。 ModelCache v0.2.0及之前版本存在安全漏洞,该漏洞源于/manager/data_manager.py反序列化不当,可能导致执行任意代码。

Description (English)

ModelCache is an LLM-sonymized cache system that enhances user experience by reducing response time through the cache search results. There is a security loophole in ModelCache v. 2.0 and earlier versions, which stems from/manager/data manager.py’s inverse sequence, which may lead to the enforcement of arbitrary codes.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

codefuse-ai

Published

2025-08-11

Last Modified

2026-02-24

References

https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/factory.py#L18C1-L18C71 https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/data_manager.py#L84C1-L84C43 https://pytorch.org/docs/stable/generated/torch.load.html https://github.com/EDMPL/Vulnerability-Research/blob/main/CVE-2025-45146/README.md https://access.redhat.com/security/cve/cve-2025-45146

Share on: