pypi package report

Is executorch safe?

2 known vulnerabilities, worst severity CRITICAL.

cvss
9.8

how bad it is if exploited, out of 10

epss
0.60%

chance of exploitation in the next 30 days

xyz score
4.6

CyberXYZ composite, out of 10

fig. 01 — GHSA-84m3-f99p-cqx5, the advisory selected below

// advisories

GHSA-84m3-f99p-cqx5

CRITICALCVE-2025-30405

An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 0830af8207240df8d7f35b984cdf8bc35d74fa73.

Affected
< 0.7.0
Fixed in
0.7.0
Weakness
CWE-190
Published
2025-08-08
Source
github

GHSANVDMITREreferencereference


// dependencies

29 direct, 7 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

3 published models

0 declared · 3 observed · 0 inferred

ModelEvidence
software-mansion/react-native-executorch-kokoroobserved
software-mansion/react-native-executorch-whisper-tinyobserved

Sign in to see all 1 models and per-model risk

3 published AI models are associated with this package: 0 name it in a requirements or pyproject file, 3 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 0 state a version requirement, so this is not a count of affected models.


Checked 2026-09-22 at 01:35 UTC. The most recent advisory here was published 2025-08-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is executorch safe? pypi package security report | CyberXYZ