logo

Remote Code Execution With Modern AI/ML Formats and Libraries

ID: deb46c7c-e4c6-5d39-b68f-410b70b45074

STIX ID: report--deb46c7c-e4c6-5d39-b68f-410b70b45074

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-28

Author: Curtis Carmony

...
...

This Unit 42 report details RCE vulnerabilities in three AI/ML Python libraries (NeMo, uni2TS, ml-flextok) that occur when malicious metadata in model files is passed to Hydra's instantiate() function, enabling arbitrary code execution when models are loaded (including models hosted on HuggingFace). The report provides technical analysis, affected models and formats, vendor disclosures and CVEs, and notes that fixes and mitigations were issued and no active exploitation was observed as of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.