CVE-2025-45146
CRITICALModelCache < 0.2.0 - Remote Code Execution via Unsafe Deserialization in Data Manager
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-45146. PoCs published by EDMPL.
AI-analyzed exploit summary The repository contains a functional PoC for CVE-2025-45146, demonstrating an insecure deserialization vulnerability in CodeFuse-AI ModelCache <= 0.2.0. The exploit uses Python's pickle library to craft a malicious payload that executes arbitrary commands (e.g., 'calc.exe') when deserialized.
Description
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.
Exploits (1)
The repository contains a functional PoC for CVE-2025-45146, demonstrating an insecure deserialization vulnerability in CodeFuse-AI ModelCache <= 0.2.0. The exploit uses Python's pickle library to craft a malicious payload that executes arbitrary commands (e.g., 'calc.exe') when deserialized.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H