CVE-2025-60455: Modular Max

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

Affected products

  • Modular Max: before 25.6.0 (fixed in 25.6.0)

Published 2025-11-18. Last modified 2026-06-17.