A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host.
References
Configurations
No configuration.
History
15 May 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-15 15:16
Updated : 2025-05-15 15:16
NVD link : CVE-2025-4701
Mitre link : CVE-2025-4701
JSON object : View
Products Affected
No product.