Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiateclass in vocos/pretrained.py takes the classpath value from the configuration, splits it into a module and an attribute, imports the module with import, resolves the attribute with getattr, and calls the result as argsclass(*args, **kwargs) where kwargs is the config's own initargs mapping. No allowlist constrains the dotted path, so a configuration may name any importable callable and supply the arguments it is called with. Vocos.fromhparams reaches this for each of the featureextractor, backbone and head entries, and Vocos.frompretrained reaches it with a remote file: it downloads config.yaml from a caller-named Hugging Face repository and passes it straight to fromhparams. Loading a model from a repository the user does not control therefore executes code of the repository owner's choosing in the loading process. The neighbouring torch.load of the downloaded weights is a separate matter and is constrained on PyTorch releases that default weights_only to true, which leaves this path as the reachable one.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79784.json",
"cwe_ids": [
"CWE-470"
],
"cna_assigner": "VulnCheck"
}