Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-23654

Опубликовано: 10 мар. 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability?

An attacker could exploit this issue by publishing a malicious package named “geneformer” to the public PyPI registry using the same name referenced in the project’s requirements file. If a user installs the affected open‑source project and the installation process retrieves this malicious package instead of an intended legitimate one, the attacker’s code could run on the user’s system during installation. This could allow the attacker to execute unauthorized code.

Обновления

ПродуктСтатьяОбновление
GitHub Repo: Zero Shot scFoundation

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Unlikely

EPSS

Процентиль: 20%
0.00065
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
17 дней назад

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
github
17 дней назад

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
fstec
17 дней назад

Уязвимость программного обеспечения Zero Shot scFoundation, связанная с наличием уязвимости в заимствованном компоненте, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 20%
0.00065
Низкий

8.8 High

CVSS3