CVE-2025-45146: Codefuse Modelcache

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.

Affected products

  • Codefuse Modelcache: up to and including 0.2.0

Published 2025-08-11. Last modified 2026-06-17.