CVE-2025-3622: Xorbits Inference model.py load deserialization

5.1 CVSS

Description

A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization. Eine Schwachstelle wurde in Xorbits Inference bis 1.4.1 entdeckt. Sie wurde als kritisch eingestuft. Hierbei geht es um die Funktion load der Datei xinference/thirdparty/cosyvoice/cli/model.py. Dank Manipulation mit unbekannten Daten kann eine deserialization-Schwachstelle ausgenutzt werden.

Classification

CVE ID: CVE-2025-3622

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.1

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem Types

Deserialization Improper Input Validation

Affected Products

Vendor: Xorbits

Product: Inference

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 13.88% (scored less or equal to compared to others)

EPSS Date: 2025-05-09 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-3622
https://vuldb.com/?id.304679
https://vuldb.com/?ctiid.304679
https://vuldb.com/?submit.552245
https://github.com/xorbitsai/inference/issues/3190
https://github.com/xorbitsai/inference/issues/3190#issuecomment-2783462266

Timeline