Skip to content

torch.load vulnerability (torch<=2.5.1)

Moderate
ego-thales published GHSA-m9mp-6x32-5rhg Oct 8, 2025

Package

pip scio (pip)

Affected versions

<=1.0.0

Patched versions

1.0.1
pip torch (pip)
<=2.5.1
2.6

Description

Impact

PyTorch reported a critical vulnerability when using torch.load, even with option weights_only=True, for torch<=2.5.1.

In scio<=1.0.0, the lower bound for torch is 2.3.

Patches

The lower bound was changed to torch>=2.6, starting from scio>=1.0.1 (currently in dev state).

Workarounds

You can manually check that you are using torch>=2.6.

References

GHSA-53q9-r3pm-6pq6

Severity

Moderate

CVE ID

CVE-2025-32434

Weaknesses

No CWEs

Credits