-
Notifications
You must be signed in to change notification settings - Fork 346
Description
Vulnerable Library - openai_whisper-20250625.tar.gz
Path to dependency file: /supporting_scripts/lecture-transcription/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20251015091536_QCFQRB/python_QUNYSB/202510150920071/env/lib/python3.9/site-packages/torch-2.8.0.dist-info
Vulnerabilities
Vulnerability | Severity | Dependency | Type | Fixed in (openai_whisper version) | Remediation Possible** | |
---|---|---|---|---|---|---|
CVE-2025-55552 | 5.3 | torch-2.8.0-cp310-none-macosx_11_0_arm64.whl | Transitive | N/A* | ❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2025-55552
Vulnerable Library - torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
Tensors and Dynamic neural networks in Python with strong GPU acceleration
Library home page: https://files.pythonhosted.org/packages/ef/d6/e6d4c57e61c2b2175d3aafbfb779926a2cfd7c32eeda7c543925dceec923/torch-2.8.0-cp310-none-macosx_11_0_arm64.whl
Path to dependency file: /supporting_scripts/lecture-transcription/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20251015091536_QCFQRB/python_QUNYSB/202510150920071/env/lib/python3.9/site-packages/torch-2.8.0.dist-info
Dependency Hierarchy:
- openai_whisper-20250625.tar.gz (Root Library)
- ❌ torch-2.8.0-cp310-none-macosx_11_0_arm64.whl (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
Publish Date: 2025-09-25
URL: CVE-2025-55552
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
Step up your Open Source Security Game with Mend here