Vulnerability Description
Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oneflow | Oneflow | 0.9.0 |
Related Weaknesses (CWE)
References
- http://oneflow.comProduct
- https://github.com/Daisy2angNot Applicable
- https://github.com/Oneflow-Inc/oneflowProduct
- https://github.com/Oneflow-Inc/oneflow/issues/10666ExploitIssue TrackingPatch
FAQ
What is CVE-2025-63397?
CVE-2025-63397 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.
How severe is CVE-2025-63397?
CVE-2025-63397 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63397?
Check the references section above for vendor advisories and patch information. Affected products include: Oneflow Oneflow.