Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
37 items
LMCache is vulnerable to Unauthenticated Remote Code Execution via Pickle Deserialization on the Multiprocess ZMQ Transport
Oct 6, 2026CriticalVulnerabilitySecurityCVE-2026-105192, rated CVSS 9.8 critical, affects lmcache versions up to and including 0.3.9 in multiprocess (distributed) mode. The ZeroMQ ROUTER transport has no authentication, and a single crafted REGISTER_KV_CACHE frame reaches pickle.loads through DeviceIPCWrapper.Deserialize during argument decoding, executing commands as the LMCache process user, which is root in official container images. The score applies when the transport is bound to a routable address rather than the default localhost.
Fix: No fixed version has been published as of 2026-10-07. The source advises stopping network data from being passed to pickle, replacing the serializer behind msgpack extension code 1 with a safe format, and not calling pickle.loads on data that a
JFrog Security Research (Vulnerabilities)CVE-2026-100308: Amazon GluonTS deserialization of untrusted data in model loading
Sep 29, 2026HighVulnerabilitySecurityCVE-2026-100308CVE-2026-100308 affects the model loading component in Amazon GluonTS before 0.17.0. Deserialization of untrusted data may allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process, via a crafted serialized model directory.
Fix: Upgrade to version 0.17.0 or later.
NVD/CVE DatabaseGHSA-2vh9-42vm-xmv2: LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
Sep 18, 2026CriticalVulnerabilitySecurityCVE-2025-66455LMDeploy's PyTorch DistServe control plane deserialized ZeroMQ messages with recv_pyobj(), which uses pickle and can execute arbitrary code during deserialization. An attacker who can reach the POST /distserve/p2p_connect endpoint can point the server at a malicious ZeroMQ peer, and deployments without API-key authentication allow unauthenticated remote code execution with the privileges of the serving process. Affected versions are lmdeploy >= 0.9.2, < 0.16.0, and only when PD-disaggregation/DistServe is enabled.
Fix: Fixed in LMDeploy 0.16.0, which replaces pickle-based ZeroMQ messaging with JSON (send_json()/recv_json()) and validates received objects against the DistServeCacheFreeRequest Pydantic schema. Interim workarounds: prevent untrusted clients from reaching /distserve/* endpoints, restrict the DistServe HTTP and ZeroMQ control planes to trusted cluster networks, configure API-key authentication, and block arbitrary outbound ZeroMQ connections from serving nodes. The source states these workarounds reduce exposure but do not make pickle deserialization safe.
GitHub Advisory DatabaseGHSA-gqvg-gmmx-x4hm: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
Sep 1, 2026HighVulnerabilitySecurityThe mlflow.statsmodels flavor's _load_model calls statsmodels.iolib.api.load_pickle, which wraps pickle.load, without checking MLFLOW_ALLOW_PICKLE_DESERIALIZATION. An attacker who can place a crafted MLmodel artifact with a malicious model.pkl in an accessible artifact store can trigger code execution in any process calling mlflow.pyfunc.load_model() on it, even when the setting is False. Default deployments without basic-auth require no credentials to upload the artifact.
Fix: Add the missing MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard to mlflow/statsmodels/__init__.py, in _load_model, raising MlflowException when pickle deserialization is not allowed.
GitHub Advisory DatabaseCVE-2026-78683: NLTK unsafe pickle deserialization in TransitionParser.parse() method
Aug 24, 2026CriticalVulnerabilitySecurityCVE-2026-78683NLTK before 3.10.0 (affected versions <=3.9.4) has an unsafe pickle deserialization flaw in TransitionParser.parse() (nltk/parse/transitionparser.py). The method calls pickle_load() with restricted=False, routing loads through WarningUnpickler, which does not override find_class(), so arbitrary class resolution is allowed. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application.
Fix: Fixed in 3.10.0.
NVD/CVE DatabaseGHSA-qxq5-qhx6-94qw: Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Aug 18, 2026HighVulnerabilitySecurityMONAI's algo_from_pickle() in monai/auto3dseg/utils.py still calls pickle.loads() on attacker-supplied files in v1.5.2, despite GHSA-89gg-p5r5-q6r4 claiming the issue was patched. The source reports that the file was last changed on 2024-07-12, that all three pickle.loads() calls remain unchanged in v1.5.1 and v1.5.2, and that the advisory's referenced patch is a Zip Slip fix. Any application passing an attacker-controlled path to this function can achieve code execution.
GitHub Advisory DatabaseCVE-2026-12484: keras-team/keras unsafe deserialization via TorchModuleWrapper.from_config
Jul 19, 2026HighVulnerabilitySecurityCVE-2026-12484CVE-2026-12484 affects keras-team/keras version 3.15.0. The public keras.layers.TorchModuleWrapper.from_config method calls torch.load(..., weights_only=False) without requiring an explicit unsafe opt-in, so it deserializes attacker-controlled PyTorch pickle data by default when no SafeModeScope(True) context is active. Processing untrusted Keras layer configurations this way can lead to arbitrary code execution.
NVD/CVE DatabaseGHSA-m8gf-v64p-gfmg: BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
Jul 10, 2026HighVulnerabilitySecurityCVE-2026-54071BabelDOC's vendored PDF parser deserializes untrusted pickle data when loading CMap files, in `babeldoc/pdfminer/cmapdb.py`. A PDF-controlled CMap name is passed to `os.path.join()` and `pickle.loads()` after only NUL bytes are stripped, so a hex-encoded absolute path in a crafted PDF's `/Encoding` name can redirect deserialization to an attacker-writable `.pickle.gz` file, giving arbitrary Python code execution with the privileges of the BabelDOC process.
GitHub Advisory DatabaseCVE-2026-54499: Stanza model loaders arbitrary code execution via malicious pickle files
Jul 8, 2026HighVulnerabilitySecurityCVE-2026-54499CVE-2026-54499 affects Stanza, the Stanford NLP Python library, before version 1.12.2. Model loaders such as stanza.models.common.pretrain.Pretrain.load() call torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) when a pickle.UnpicklingError is raised. An attacker-controlled malicious .pt pretrain or model file can therefore execute arbitrary pickle code when a Stanza NLP pipeline loads it.
Fix: Fixed in 1.12.2.
NVD/CVE DatabaseCVE-2025-71372: Picklescan fails to detect numpy f2py gadget in pickle __reduce__ methods
Jul 3, 2026HighVulnerabilitySecurityCVE-2025-71372CVE-2025-71372 affects Picklescan before 0.0.33. The scanner fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, so crafted pickle files that execute arbitrary Python code when loaded pass its safety checks. The flaw enables supply-chain poisoning of shared model files. VulnCheck rates it CVSS 4.0 7.6 (HIGH), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-71342: picklescan fails to detect malicious pickles via idlelib.run.Executive.runcode
Jul 3, 2026HighVulnerabilitySecurityCVE-2025-71342CVE-2025-71342 affects picklescan before 0.0.30, which fails to detect malicious pickle files that use idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks. VulnCheck rates it CVSS 4.0 7.6 HIGH, and NIST has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-71340: picklescan fails to detect malicious pickle files invoking runcode in __reduce__
Jun 25, 2026HighVulnerabilitySecurityCVE-2025-71340picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code that runs arbitrary commands when the file is loaded via pickle.load(), enabling supply chain attacks on PyTorch models and saved Python objects.
Fix: This is fixed in version 0.0.30.
NVD/CVE DatabaseGHSA-q8gq-377p-jq3r: vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
Jun 16, 2026HighVulnerabilitySecurityCVE-2026-41523An assert-based security check in vLLM's activation function loading, at vllm/model_executor/layers/pooler/activations.py:48, restricts which functions can be loaded from a HuggingFace model's config.json. When vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1), Python strips the assert, so an attacker-published malicious model can pass an arbitrary function_name to resolve_obj_by_qualname() and execute code during model initialization. The attack requires the victim to load the malicious model and the model to use a cross-encoder architecture.
Fix: Suggested fix: replace the assert with an explicit conditional raise: if not function_name.startswith("torch.nn.modules."): raise ValueError("Loading of activation functions is restricted to torch.nn.modules for security reasons"). The source text ends mid-sentence at "A fix for this", so no released fixed version is stated.
Hugging Face Security AdvisoriesGHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
Jun 3, 2026HighVulnerabilitySecurityCVE-2026-5241A flaw in the LightGlue model loading path of huggingface/transformers 5.2.0 lets an attacker-controlled model repository run arbitrary code during model initialization. The `trust_remote_code` value, meant to block remote code, is overridden by the `trust_remote_code` setting read from the untrusted `config.json` and passed into nested `AutoConfig.from_pretrained()` calls. Code runs even when the victim calls `AutoModel.from_pretrained()` with `trust_remote_code=False`. The source rates the risk as high for inference servers, notebooks, CI/CD pipelines and evaluation workers, citing possible credential theft, lateral movement and persistence.
GitHub Advisory DatabaseCVE-2026-47117: OpenMed remote code execution in PII privacy-filter model loading
Jun 2, 2026CriticalVulnerabilitySecurityCVE-2026-47117CVE-2026-47117 affects OpenMed before 1.5.2, where the PII privacy-filter model loading path contains a remote code execution flaw. The privacy-filter dispatcher applied broad substring matching to the user-supplied model_name parameter, so a value such as attacker/foo-privacy-filter-bar routed to a path that loads Hugging Face models with trust_remote_code=True. An unauthenticated attacker who supplies a malicious model repository with custom code referenced through auto_map in config.json or tokenizer_config.json gets that code imported and executed with the privileges of the OpenMed service process.
NVD/CVE DatabaseGHSA-xmpw-2vmm-p4p6: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
May 19, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-45758A malicious version, guardrails-ai 0.10.1, was published to PyPI on May 11, 2026 at approximately 6:00 PM Pacific by an attacker. Anyone who installed guardrails-ai==0.10.1 from PyPI that day is affected, and PyPI quarantined the repository after researchers identified the package within about 2 hours. The maintainers report no requests to Guardrails AI infrastructure from the malicious version and no evidence of user data exfiltration through their systems.
Fix: Downgrade to guardrails-ai==0.10.0, which is unaffected, since no patched version above 0.10.1 is available yet. While the PyPI quarantine is active, install from GitHub with pip install git+https://github.com/guardrails-ai/guardrails.git@v0.10.0. If 0.10.1 was installed, treat the host as potentially compromised, rotate any credentials accessible from it (GitHub PATs, cloud provider keys, package registry tokens, API keys), and audit the GitHub account for unauthorized workflows or repositories. Snowglobe and Guardrails Hub API keys will be invalidated at 2:00 PM Pacific on May 13, 2026, so rotate them before then.
GitHub Advisory DatabaseCVE-2026-31239: mamba language model framework insecure deserialization when loading models
May 12, 2026HighVulnerabilitySecurityCVE-2026-31239The mamba language model framework through 2.2.6 is affected by insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method calls torch.load() on pytorch_model.bin without setting weights_only=True, so arbitrary Python objects can be deserialized via the pickle module. An attacker who publishes a malicious model repository can execute arbitrary code on a victim's system, in the context of the mamba process, when the victim loads a model from it.
NVD/CVE DatabaseCVE-2026-31232: CosyVoice insecure deserialization in model loading via torch.load
May 12, 2026HighVulnerabilitySecurityCVE-2026-31232CVE-2026-31232 affects the CosyVoice project through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) and is classified as CWE-502. The model loading process calls torch.load() without weights_only=True when reading .pt files from a directory passed via --model_dir, so arbitrary Python objects can be deserialized through Pickle. An attacker who supplies a crafted model directory can trigger remote code execution on a victim who loads it through the CosyVoice web interface.
NVD/CVE DatabaseCVE-2026-31229: The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in…
May 12, 2026HighVulnerabilitySecurityCVE-2026-31229The Adversarial Robustness Toolbox (ART) through 1.20.1 contains an insecure deserialization flaw (CWE-502) in its Kubeflow component's model loading. During robustness evaluation, model weights loaded from a file such as model.pt use torch.load() without weights_only=True, which permits Pickle deserialization of arbitrary Python objects. An attacker who uploads a crafted model file to object storage referenced by the pipeline, or who controls the model_id parameter to point to such a file, can achieve remote code execution when the pipeline loads the model.
NVD/CVE DatabaseCVE-2026-31223: snorkel insecure deserialization in BaseLabeler.load() via pickle files
May 12, 2026CriticalVulnerabilitySecurityCVE-2026-31223CVE-2026-31223 affects the snorkel library through v0.10.0 and is classified as CWE-502, insecure deserialization. The BaseLabeler.load() method passes user-supplied file paths to pickle.load() with no validation or security controls. A remote attacker who supplies a maliciously crafted pickle file can achieve arbitrary code execution when the file is loaded through this method.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.