VulnerabilityAnalyzed
CVE-2025-60455
Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.
HIGH 8.4EPSS 0.31%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.
- CVSS 3.1
- 8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- modular/max
- Source
- cve@mitre.org
References
- https://github.com/modular/modular/blame/main/max/serve/kvcache_agent/kvcache_agent.py#L220Broken Link
- https://github.com/modular/modular/commit/10620059fb5c47fb0c30e5d21a8ff3b8d622fba4Patch
- https://github.com/modular/modular/commit/b20e749fa892dbe772e890a268002f732164d9f5Patch
- https://github.com/modular/modular/commit/ee9c4ab02345dd30bed8b79771b6909ff1b930a1Patch
- https://github.com/modular/modular/issues/4795Issue Tracking, Patch
- https://www.oligo.security/blog/shadowmq-how-code-reuse-spread-critical-vulnerabilities-across-the-ai-ecosystemExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.