{"apiVersion":"1.0","identifier":"CVE-2026-76843","description":"The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker-s code with the privileges of the loading process. This is the same sink and the same file as CVE-2024-10073, which records 0.15.0 as the fixed version on the basis that clustering support was dropped in that release; the module was removed from the documented API but remains present in the distributed artifact and reachable by importing flair.models.clustering directly, so the earlier record-s fixed version does not hold for the shipped package.","publishedAt":"2026-08-24T14:17:02","lastModifiedAt":"2026-08-28T16:18:25","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76843","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00147,"riskScore":0.79,"affectedProduct":"flair","affectedVersions":">=0.15.0,<=0.15.1","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76843","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76843","en":"https://www.redsauce.net/en/cves/CVE-2026-76843","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76843","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76843","de":"https://www.redsauce.net/de/cves/CVE-2026-76843","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76843","el":"https://www.redsauce.net/el/cves/CVE-2026-76843"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76843"}}