Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.
| Score | Percentile |
|---|---|
| 0.05% | 14.98% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-7xcv-9j6c-2fmc ↗ |
| CVE | CVE-2025-60455 ↗ |
| CWE id | Name |
|---|---|
| CWE-502 | Deserialization of Untrusted Data |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | modular | < 25.6.0 | 25.6.0 | — |