CVE-2025-46567 | hiyouga LLaMA-Factory up to 0.x llamafy_baichuan2.py torch.load deserialization (GHSA-f2f7-gj54-6vpv)
A vulnerability, which was classified as problematic, was found in hiyouga LLaMA-Factory up to 0.x. This affects the function torch.load of the file llamafy_baichuan2.py. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-46567. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.