CVE-2025-3622
MEDIUMXorbits Inference <1.4.1 - Deserialization
Title source: llmDescription
A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
37.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
CWE-20
Status
draft
Timeline
Published
Apr 15, 2025
Tracked Since
Feb 18, 2026