{"data":{"id":"843d2d80-7c4b-41eb-a52f-8df5488928c2","title":"CVE-2026-100308: Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow…","summary":"CVE-2026-100308 affects the model loading component in Amazon GluonTS before 0.17.0. Deserialization of untrusted data may allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process, via a crafted serialized model directory.","solution":"Upgrade to version 0.17.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100308","publishedAt":"2026-09-29T16:17:04.900Z","cveId":"CVE-2026-100308","cweIds":["CWE-470","CWE-502"],"cvssScore":"7.8","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Amazon GluonTS"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Amazon GluonTS deserialization of untrusted data in model loading","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"local","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00136,"epssCheckedAt":"2026-10-10T06:42:01.216Z","kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:08.560Z","patchAvailable":null,"disclosureDate":"2026-09-29T16:17:04.900Z","capecIds":["CAPEC-586"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}