CVE-2025-5148

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads to deserialization. An attack has to be approached locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is 784cbf8dde2cf1456ff808aeba23177e1810e7a9. It is recommended to apply a patch to fix this issue.
Configurations

No configuration.

History

28 May 2025, 14:58

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en FunAudioLLM InspireMusic hasta bf32364bcb0d136497ca69f9db622e9216b029dd. Se ha clasificado como crítica. La función load_state_dict del archivo inspiremusic/cli/model.py del componente Pickle Data Handler se ve afectada. La manipulación provoca la deserialización. Un ataque debe abordarse localmente. Este producto utiliza una versión continua para garantizar una distribución continua. Por lo tanto, no se dispone de detalles de las versiones afectadas ni de las actualizadas. El nombre del parche es 784cbf8dde2cf1456ff808aeba23177e1810e7a9. Se recomienda aplicar un parche para solucionar este problema.

25 May 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-25 12:15

Updated : 2025-05-28 14:58


NVD link : CVE-2025-5148

Mitre link : CVE-2025-5148

CVE.ORG link : CVE-2025-5148


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data