← Volver al buscador de CVEs

CVE-2026-76843

flair

Descripción

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker-s code with the privileges of the loading process. This is the same sink and the same file as CVE-2024-10073, which records 0.15.0 as the fixed version on the basis that clustering support was dropped in that release; the module was removed from the documented API but remains present in the distributed artifact and reachable by importing flair.models.clustering directly, so the earlier record-s fixed version does not hold for the shipped package.

CVSS 7.8EPSS 0.147%Riesgo 0.79
Ver fuente
Publicación
2026-08-24 14:17:02
Versiones afectadas
>=0.15.0,<=0.15.1
Tipo
Librería
Última modificación
2026-08-24 19:17:00
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H