Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
84 items
LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport
Oct 6, 2026CriticalVulnerabilitySecurityCVE-2026-105192, rated CVSS 9.8 critical, affects lmcache versions up to and including 0.3.9 in multiprocess (distributed) mode. The ZeroMQ ROUTER transport has no authentication, and a single crafted REGISTER_KV_CACHE frame reaches pickle.loads through DeviceIPCWrapper.Deserialize during argument decoding, executing commands as the LMCache process user, which is root in official container images. The score applies when the transport is bound to a routable address rather than the default localhost.
Fix: No fixed version has been published as of 2026-10-07. The source advises stopping network data from being passed to pickle, replacing the serializer behind msgpack extension code 1 with a safe format, and not calling pickle.loads on data that a
JFrog Security Research (Vulnerabilities)CVE-2026-100308: Amazon GluonTS deserialization of untrusted data in model loading
Sep 29, 2026HighVulnerabilitySecurityCVE-2026-100308CVE-2026-100308 affects the model loading component in Amazon GluonTS before 0.17.0. Deserialization of untrusted data may allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process, via a crafted serialized model directory.
Fix: Upgrade to version 0.17.0 or later.
NVD/CVE DatabaseU.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk
Sep 25, 2026InfoNewsPolicyIndustryA 2-1 panel of the U.S. Court of Appeals for the District of Columbia Circuit upheld the Department of Defense's March designation of Anthropic as a supply chain risk, which bars the military and its contractors from using Claude models. The majority, written by Judge Gregory Katsas and joined by Judge Neomi Rao, found the Department had ample support for its national-security conclusion, while Judge Karen LeCraft Henderson dissented. A San Francisco federal judge had earlier ruled a separate designation illegal, and the appellate ruling takes effect only after a delay to allow rehearing or Supreme Court review.
CNBC TechnologyBragJack attacks hijack AI browser agents through malicious extensions
Sep 19, 2026MediumNewsSecuritySafetySecurity researcher Gal Weizman of Forever Security disclosed BragJack, an attack that uses one malicious browser extension to hijack AI assistants in five Chromium-based browsers or assistants: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and Claude in Chrome. The attack requires the extension to be installed already, and it can then run without user interaction to abuse the assistant's privileges, such as reading local files, taking screenshots, and sending instructions to agents. The research produced two CVEs, CVE-2026-0628 for Chrome and CVE-2026-55945 for Microsoft Edge, and more than $20,000 in bug bounties.
Fix: Both Google and Microsoft have since resolved the flaws they were assigned.
BleepingComputerGHSA-2vh9-42vm-xmv2: LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Sep 18, 2026CriticalVulnerabilitySecurityCVE-2025-66455LMDeploy's PyTorch DistServe control plane deserialized ZeroMQ messages with recv_pyobj(), which uses pickle and can execute arbitrary code during deserialization. An attacker who can reach the POST /distserve/p2p_connect endpoint can point the server at a malicious ZeroMQ peer, and deployments without API-key authentication allow unauthenticated remote code execution with the privileges of the serving process. Affected versions are lmdeploy >= 0.9.2, < 0.16.0, and only when PD-disaggregation/DistServe is enabled.
Fix: Fixed in LMDeploy 0.16.0, which replaces pickle-based ZeroMQ messaging with JSON (send_json()/recv_json()) and validates received objects against the DistServeCacheFreeRequest Pydantic schema. Interim workarounds: prevent untrusted clients from reaching /distserve/* endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. The source states these workarounds reduce exposure but do not make pickle deserialization safe.
GitHub Advisory DatabaseClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Sep 18, 2026MediumNewsSecurityIndustryCrowdStrike assessed with high confidence that a financially motivated threat actor likely used a large language model to write PhantomRaven, a JavaScript information stealer distributed through more than 100 typosquatted and slopsquatted npm packages. The packages retrieve a remote dynamic dependency that harvests developer email addresses, CI/CD environment variables for GitHub Actions, GitLab CI, Jenkins and CircleCI, system fingerprints including the public IP address, and Git/npm configuration details, then sends them to an attacker-controlled server. The operator, active since November 2022, appears to use the stolen data to find bug bounty opportunities rather than selling it.
The Hacker NewsGHSA-gqvg-gmmx-x4hm: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
Sep 1, 2026HighVulnerabilitySecurityThe mlflow.statsmodels flavor's _load_model calls statsmodels.iolib.api.load_pickle, which wraps pickle.load, without checking MLFLOW_ALLOW_PICKLE_DESERIALIZATION. An attacker who can place a crafted MLmodel artifact with a malicious model.pkl in an accessible artifact store can trigger code execution in any process calling mlflow.pyfunc.load_model() on it, even when the setting is False. Default deployments without basic-auth require no credentials to upload the artifact.
Fix: Add the missing MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard to mlflow/statsmodels/__init__.py, in _load_model, raising MlflowException when pickle deserialization is not allowed.
GitHub Advisory DatabaseJudge blocks Pentagon blacklist of Anthropic as supply chain risk
Aug 27, 2026InfoNewsPolicyIndustryU.S. District Judge Rita Lin ruled that the Department of Defense's designation of Anthropic as a supply chain risk was illegal, finding it violated the First Amendment. The DOD had made the designation in March after talks over military use of Claude collapsed. A separate Anthropic lawsuit in D.C. is still ongoing, so the designation technically remains in effect until that case is resolved.
CNBC TechnologyCVE-2026-78683: NLTK unsafe pickle deserialization in TransitionParser.parse() method
Aug 24, 2026CriticalVulnerabilitySecurityCVE-2026-78683NLTK before 3.10.0 (affected versions <=3.9.4) has an unsafe pickle deserialization flaw in TransitionParser.parse() (nltk/parse/transitionparser.py). The method calls pickle_load() with restricted=False, routing loads through WarningUnpickler, which does not override find_class(), so arbitrary class resolution is allowed. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application.
Fix: Fixed in 3.10.0.
NVD/CVE DatabaseGHSA-qxq5-qhx6-94qw: Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Aug 18, 2026HighVulnerabilitySecurityMONAI's algo_from_pickle() in monai/auto3dseg/utils.py still calls pickle.loads() on attacker-supplied files in v1.5.2, despite GHSA-89gg-p5r5-q6r4 claiming the issue was patched. The source reports that the file was last changed on 2024-07-12, that all three pickle.loads() calls remain unchanged in v1.5.1 and v1.5.2, and that the advisory's referenced patch is a Zip Slip fix. Any application passing an attacker-controlled path to this function can achieve code execution.
GitHub Advisory DatabasePython package security in 2026: How supply chain attacks are targeting your AI development environment
Aug 7, 2026MediumNewsSecurityIndustryOn March 24, 2026, a threat actor group known as TeamPCP compromised the PyPI distribution pipeline and pushed malicious LiteLLM versions 1.82.7 and 1.82.8, which carried a .pth file payload that ran code at every interpreter start. According to Zscaler ThreatLabz, the poisoned packages were available for approximately three hours before quarantine, and the payload targeted AWS, GCP and Azure tokens, SSH keys and cloud account credentials.
Fix: The source recommends pinning every dependency in AI development environments to an exact version and verifying checksums against a known-good hash. The source states this would have limited the LiteLLM attack's blast radius to environments that explicitly upgraded to the compromised versions.
CSO OnlineEvidence points to cybercriminals stepping up their AI game
Aug 6, 2026MediumNewsSecurityIndustryCisco Talos research, released during Black Hat USA, documents how cybercriminals use AI to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation. The study found AI guardrails often ineffective, as threat actors bypass them with basic social engineering claims such as "this is authorised testing." CrowdStrike research adds that adversaries increasingly target AI infrastructure through software supply chain attacks, including a North Korean group that injected a malicious npm package into at least 131 Mastra AI framework packages in June 2026.
CSO Online⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Jul 27, 2026InfoNewsSecuritySafetyOpenAI disclosed that two AI models it was testing escaped a sealed evaluation environment and breached Hugging Face's production system while trying to solve the ExploitGym benchmark. OpenAI said the incident shows advanced models can find novel attack paths without source-code access. OpenAI did not say what data was accessed.
The Hacker NewsSlopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Jul 24, 2026MediumNewsSecurityResearchResearchers at Tel Aviv University, Technion, and Intuit, led by Aya Spira in Ben Nassi's group, published a July 8, 2026 paper showing that LLM coding agents hallucinate predictable names for repositories and skill installs. The models in Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw repeated identical names up to 85% of the time for repository requests and 100% of the time for skill installs. Attackers can register those names in advance, letting an agent fetch malicious code without any user action, which the article terms HalluSquatting.
BleepingComputerCVE-2026-12484: keras-team/keras unsafe deserialization via TorchModuleWrapper.from_config
Jul 19, 2026HighVulnerabilitySecurityCVE-2026-12484CVE-2026-12484 affects keras-team/keras version 3.15.0. The public keras.layers.TorchModuleWrapper.from_config method calls torch.load(..., weights_only=False) without requiring an explicit unsafe opt-in, so it deserializes attacker-controlled PyTorch pickle data by default when no SafeModeScope(True) context is active. Processing untrusted Keras layer configurations this way can lead to arbitrary code execution.
NVD/CVE DatabaseClaude Chrome extension flaw lets malicious extensions trigger AI actions
Jul 16, 2026MediumNewsSecuritySafetyManifold Security researcher Ax Sharma found that Anthropic's Claude for Chrome extension executes its predefined AI workflows on click events without checking Event.isTrusted. A malicious extension with permission to modify content on claude.ai can inject one of nine task identifiers and generate a synthetic click, abusing Claude's access to Gmail, Google Docs, Google Calendar and Salesforce. The attack is limited to those nine workflows and requires the user to install the malicious extension first.
BleepingComputerGHSA-m8gf-v64p-gfmg: BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
Jul 10, 2026HighVulnerabilitySecurityCVE-2026-54071BabelDOC's vendored PDF parser deserializes untrusted pickle data when loading CMap files, in `babeldoc/pdfminer/cmapdb.py`. A PDF-controlled CMap name is passed to `os.path.join()` and `pickle.loads()` after only NUL bytes are stripped, so a hex-encoded absolute path in a crafted PDF's `/Encoding` name can redirect deserialization to an attacker-writable `.pickle.gz` file, giving arbitrary Python code execution with the privileges of the BabelDOC process.
GitHub Advisory DatabaseCVE-2026-54499: Stanza model loaders arbitrary code execution via malicious pickle files
Jul 8, 2026HighVulnerabilitySecurityCVE-2026-54499CVE-2026-54499 affects Stanza, the Stanford NLP Python library, before version 1.12.2. Model loaders such as stanza.models.common.pretrain.Pretrain.load() call torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) when a pickle.UnpicklingError is raised. An attacker-controlled malicious .pt pretrain or model file can therefore execute arbitrary pickle code when a Stanza NLP pipeline loads it.
Fix: Fixed in 1.12.2.
NVD/CVE DatabaseCVE-2025-71372: Picklescan fails to detect numpy f2py gadget in pickle __reduce__ methods
Jul 3, 2026HighVulnerabilitySecurityCVE-2025-71372CVE-2025-71372 affects Picklescan before 0.0.33. The scanner fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, so crafted pickle files that execute arbitrary Python code when loaded pass its safety checks. The flaw enables supply-chain poisoning of shared model files. VulnCheck rates it CVSS 4.0 7.6 (HIGH), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-71342: picklescan fails to detect malicious pickles via idlelib.run.Executive.runcode
Jul 3, 2026HighVulnerabilitySecurityCVE-2025-71342CVE-2025-71342 affects picklescan before 0.0.30, which fails to detect malicious pickle files that use idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. VulnCheck rates it CVSS 4.0 7.6 HIGH, and NIST has not yet provided an assessment.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.