{"data":{"id":"4e9e7dea-3765-497d-ae4d-950f2c6bf72f","title":"CVE-2026-79785: X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto","summary":"X-AnyLabeling's model downloader has a serious security flaw where it disables TLS certificate verification (the process that confirms you're connecting to the real website and not an imposter), allowing attackers who can intercept internet traffic to replace downloaded AI models with malicious ones. The application only checks if downloaded files are valid formats, not whether they came from a trusted source, so attackers can inject malicious code that executes when the model runs.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79785","publishedAt":"2026-08-25T16:17:30.690Z","cveId":"CVE-2026-79785","cweIds":["CWE-295"],"cvssScore":"5.9","cvssSeverity":"medium","severity":"medium","attackType":["supply_chain","model_theft"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["X-AnyLabeling","SAM2","YOLOE","UPN","open_vision"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-25T16:17:30.690Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}