Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
37 items
CVE-2026-31252: CosyVoice insecure deserialization in model loading via torch.load
May 11, 2026HighVulnerabilitySecurityCVE-2026-31252CosyVoice, through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21), has an insecure deserialization flaw (CWE-502) in its model loading component. The framework calls torch.load() on model weight files such as llm.pt, flow.pt and hift.pt without weights_only=True, so arbitrary Python objects can be deserialized through the pickle module. When a victim starts the CosyVoice Web UI pointing at a malicious model directory, arbitrary code runs on their system during model loading.
NVD/CVE DatabaseCVE-2026-31251: CosyVoice insecure deserialization in gRPC server model loading
May 11, 2026HighVulnerabilitySecurityCVE-2026-31251CosyVoice, through commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21), has an insecure deserialization flaw (CWE-502) in its gRPC server component. On startup, the server loads the speech synthesis model from a user-specified directory with torch.load() without weights_only=True, so pickle can deserialize arbitrary Python objects. An attacker who places malicious model files in a directory that a victim points the server to gains arbitrary code execution during server initialization.
NVD/CVE DatabaseGHSA-c2jg-5cp7-6wc7: Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
Apr 23, 2026CriticalVulnerabilitySecurityCVE-2025-62373A critical flaw in Pipecat's LivekitFrameSerializer, an optional, non-default, undocumented serializer deprecated in version 0.0.90, passes untrusted WebSocket message data directly to pickle.loads() in deserialize() in src/pipecat/serializers/livekit.py. A remote client that can reach a server using this serializer, for example one bound to 0.0.0.0, can send a crafted pickle payload to execute arbitrary code on the server with the Pipecat service's privileges.
GitHub Advisory DatabaseCVE-2026-6859: InstructLab code execution via untrusted HuggingFace model loading
Apr 22, 2026HighVulnerabilitySecurityCVE-2026-6859CVE-2026-6859 affects InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace, so a remote attacker can achieve arbitrary Python code execution by persuading a user to run `ilab train/download/generate` with a crafted malicious model from the HuggingFace Hub. The weakness is classified as CWE-829, and NVD had not yet provided an assessment at publication.
NVD/CVE DatabaseGHSA-hqmj-h5c6-369m: ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
Mar 16, 2026HighVulnerabilitySecurityIndustryCVE-2026-28500onnx.hub.load() skips its trust check for untrusted model repositories when silent=True is passed, so no warning or confirmation prompt appears. The source states that the SHA256 check validates against a manifest that the attacker controls, so a malicious model can carry a matching hash. The source says that when chained with file-system vulnerabilities, a model loaded this way can silently exfiltrate files such as SSH keys and cloud credentials.
GitHub Advisory DatabaseGHSA-5hwf-rc88-82xm: Fickling missing RCE-capable modules in UNSAFE_IMPORTS
Mar 4, 2026HighVulnerabilitySecurityfickling versions up to and including 0.1.8 have an incomplete UNSAFE_IMPORTS blocklist that omits the stdlib modules uuid, _osx_support and _aix_support. Functions in these modules, such as uuid._get_command_stdout, _aix_support._read_cmd_output and _osx_support._find_build_tool, call subprocess.Popen() or os.system() with attacker-controlled arguments. A malicious pickle importing them passes fickling's UnsafeImports and NonStandardImports checks, and pickle.loads() runs the command.
Fix: Assessment: the modules uuid, _osx_support and _aix_support were added to the blocklist of unsafe imports (https://github.com/trailofbits/fickling/commit/ffac3479dbb97a7a1592d85991888562d34dd05b).
GitHub Advisory DatabaseGHSA-mhc9-48gj-9gp3: Fickling has safety check bypass via REDUCE+BUILD opcode sequence
Feb 25, 2026MediumVulnerabilitySecurityThe Fickling pickle analyzer's five safety interfaces (is_likely_safe(), check_safety(), the --check-safety CLI flag, always_check_safety(), and the check_safety() context manager) report LIKELY_SAFE for pickle files that call dangerous stdlib functions when a REDUCE opcode is followed by a BUILD opcode. The reporter shows this enables a backdoor network listener, process persistence, outbound exfiltration via smtplib.SMTP, and file creation, and that appending a trivial BUILD opcode eliminates detection. Affected versions are all versions through 0.1.7.
Fix: The source states: "It is believed that the analysis pass works as intended, `REDUCE` and `BUILD` are not at fault here. The few potentially unsafe modules have been added to the blocklist (https://github.com/trailofbits/fickling/commit/0c4558d950daf70e134090573450ddcedaf10400)."
GitHub Advisory DatabaseCVE-2026-1669: Keras arbitrary file read in model loading via HDF5 integration
Feb 11, 2026HighVulnerabilitySecurityCVE-2026-1669CVE-2026-1669 is an arbitrary file read flaw in the model loading mechanism (HDF5 integration) of Keras versions 3.0.0 through 3.13.1 on all supported platforms. A remote attacker can use a crafted .keras model file with HDF5 external dataset references to read local files and disclose sensitive information. Google Inc. rated it CVSS 4.0 7.1 (High), with network attack vector, no privileges required, and user interaction required.
NVD/CVE DatabaseCVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index.load_from_disk
Jan 12, 2026HighVulnerabilitySecurityCVE-2024-14021CVE-2024-14021 affects LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6. The unsafe deserialization flaw sits in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py, which calls pickle.load() on multi_embed_store.pkl from a user-supplied persist_dir without validation. An attacker who supplies a crafted persist directory containing a malicious pickle file can achieve arbitrary code execution when a victim loads the index from disk. VulnCheck rates it CVSS 4.0 8.4 (High); NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-14921: Hugging Face Transformers code execution via deserialization of model files
Dec 23, 2025HighVulnerabilitySecurityCVE-2025-14921CVE-2025-14921 is a remote code execution flaw in the Transformer-XL model handling of Hugging Face Transformers. The flaw sits in the parsing of model files, where user-supplied data is not properly validated, leading to deserialization of untrusted data. A remote attacker can execute code in the context of the current user, provided the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2025-14920: Hugging Face Transformers Perceiver deserialization leads to code execution
Dec 23, 2025HighVulnerabilitySecurityCVE-2025-14920CVE-2025-14920 is a remote code execution flaw in the Perceiver model of Hugging Face Transformers, caused by deserialization of untrusted data during parsing of model files. A remote attacker can run arbitrary code in the context of the current user, but only if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseGHSA-m84c-4c34-28gf: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
Jul 6, 2025MediumVulnerabilitySecurityCVE-2025-3108The run-llama/llama_index library's JsonPickleSerializer component, in versions v0.12.27 through v0.12.40, falls back to Python's pickle module. Its deserialization calls pickle.loads(), so processing untrusted data can execute arbitrary code, and attackers can craft malicious payloads to achieve full system compromise. The root cause is an insecure fallback strategy without sufficient input validation or protective safeguards.
Fix: Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things.
GitHub Advisory DatabaseCVE-2025-1945: picklescan flaw lets malicious pickles hide in PyTorch model ZIP archives
Mar 10, 2025CriticalVulnerabilitySecurityCVE-2025-1945picklescan before 0.0.23 fails to detect malicious pickle files embedded in PyTorch model archives when specific ZIP header flag bits are flipped. Such a file still loads through torch.load(), which can lead to arbitrary code execution when a compromised model is loaded. The source gives a Sonatype CVSS 4.0 score of 5.3 (MEDIUM) and CWE-345, while NIST's assessment is not yet provided.
Fix: The source links a fix commit (github.com/mmaitre314/picklescan/commit/e58e45e0d9e091159c1554f9b04828bbb40b9781) and advisory GHSA-w8jq-xcqf-f792, and the title indicates the issue is fixed in picklescan 0.0.23 or later.
NVD/CVE DatabaseCVE-2024-53880: NVIDIA Triton Inference Server integer overflow in model loading API
Feb 12, 2025MediumVulnerabilitySecurityCVE-2024-53880NVIDIA Triton Inference Server contains an integer overflow or wraparound vulnerability (CWE-190) in its model loading API. A user who loads a model with an extra-large file size can overflow an internal variable, which may lead to denial of service.
NVD/CVE DatabaseCVE-2024-11394: Hugging Face Transformers Trax model deserialization remote code execution
Nov 22, 2024HighVulnerabilitySecurityCVE-2024-11394CVE-2024-11394 is a remote code execution flaw in Hugging Face Transformers' handling of Trax model files. The component fails to validate user-supplied data, leading to deserialization of untrusted data. An attacker can run code in the context of the current user if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2024-11393: Hugging Face Transformers MaskFormer deserialization flaw enables code execution
Nov 22, 2024HighVulnerabilitySecurityCVE-2024-11393CVE-2024-11393 is a remote code execution flaw in the MaskFormer model of Hugging Face Transformers. The flaw sits in the parsing of model files, where user-supplied data is not properly validated, leading to deserialization of untrusted data. A remote attacker can run arbitrary code in the context of the current user, but only if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2024-5998: langchain FAISS.deserialize_from_bytes unsafe pickle deserialization
Sep 17, 2024HighVulnerabilitySecurityCVE-2024-5998CVE-2024-5998 affects the FAISS.deserialize_from_bytes function in langchain-ai/langchain, which allows pickle deserialization of untrusted data. The issue affects the latest version of the product, and it can lead to the execution of arbitrary commands via the os.system function. The weakness is classified as CWE-502, Deserialization of Untrusted Data.
Fix: The source links a patch in the langchain-ai/langchain commit 604dfe2d99246b0c09f047c604f0c63eafba31e7, but it does not state a fixed version or a configuration change.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.