Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63767

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious reduce methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process.

EPSS

Процентиль: 51%
0.00742
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
github
23 дня назад

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process.

EPSS

Процентиль: 51%
0.00742
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502