CVE-2026-79784

Source
https://cve.org/CVERecord?id=CVE-2026-79784
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79784.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79784
Published
2026-08-25T15:16:12.456Z
Modified
2026-08-28T11:30:16.410217402Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in Model Configuration
Details

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiateclass in vocos/pretrained.py takes the classpath value from the configuration, splits it into a module and an attribute, imports the module with import, resolves the attribute with getattr, and calls the result as argsclass(*args, **kwargs) where kwargs is the config's own initargs mapping. No allowlist constrains the dotted path, so a configuration may name any importable callable and supply the arguments it is called with. Vocos.fromhparams reaches this for each of the featureextractor, backbone and head entries, and Vocos.frompretrained reaches it with a remote file: it downloads config.yaml from a caller-named Hugging Face repository and passes it straight to fromhparams. Loading a model from a repository the user does not control therefore executes code of the repository owner's choosing in the loading process. The neighbouring torch.load of the downloaded weights is a separate matter and is constrained on PyTorch releases that default weights_only to true, which leaves this path as the reachable one.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79784.json",
    "cwe_ids": [
        "CWE-470"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/gemelo-ai/vocos

Affected ranges

Type
GIT
Repo
https://github.com/gemelo-ai/vocos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.1.0"
        }
    ]
}

Affected versions

v0.*
v0.0.1
v0.0.2
v0.0.3
v0.0.4
v0.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79784.json"