modular@25.3.0 vulnerabilities

A suite of AI libraries and tools that accelerates model serving and provides programmability all the way to the GPU kernels

Direct Vulnerabilities

Known vulnerabilities in the modular package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Deserialization of Untrusted Data

modular is an A suite of AI libraries and tools that accelerates model serving and provides programmability all the way to the GPU kernels

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the kvcache_agent process when the "--experimental-enable-kvcache-agent" feature is enabled. An attacker can achieve arbitrary code execution by supplying crafted serialized data. This is only exploitable if the experimental feature is explicitly enabled.

How to fix Deserialization of Untrusted Data?

Upgrade modular to version 25.6.0 or higher.

[,25.6.0)