216.73.216.233

CVE-2026-47117

· Published 02/06/2026 16:16 · Modified 02/06/2026 17:18

Labels: CVE-2026-47117 2026-06-02CVE-2026-47117CWE-94[email protected]

Essential information

Published
02/06/2026 16:16
Modified
02/06/2026 17:18
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging Face models with trust_remote_code=True. An unauthenticated attacker can supply a malicious model repository containing custom Transformers code via auto_map in config.json or tokenizer_config.json, which is imported and executed with the privileges of the OpenMed service process.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openmed / openmed cpe:2.3:a:openmed:openmed:<1.5.2:*:*:*:*:*:*:*

References