CVE-2025-10164
CVE-2025-10164 is a high-severity deserialization vulnerability in lmsys sglang version 0.4.6, specifically within the main function of the /update_weights_from_tensor file. This flaw allows remote attackers to manipulate the serialized_named_tensors argument, leading to arbitrary code execution. With a CVSS score of 7.3, the vulnerability is easily exploitable over the network without user interaction, potentially impacting confidentiality, integrity, and availability. An exploit has been publicly released, though there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lmsys | Sglang | 0.4.6CNA affected |
CVSS Data
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.