CVE-2026-94091

Source
https://cve.org/CVERecord?id=CVE-2026-94091
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94091.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94091
Published
2026-09-20T22:15:11Z
Modified
2026-09-23T03:30:25Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
piskvorky gensim Model Loader utils.py load deserialization
Details

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Maintainer closed #3663 same-day with no comment, PR, or fix; repo's last push (2025-11-01) predates the report, so the unsafe pickle.load in SaveLoad.load remains unguarded at develop HEAD.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-20",
        "CWE-502"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94091.json"
}
References

Affected packages

Git / github.com/piskvorky/gensim

Affected ranges

Type
GIT
Repo
https://github.com/piskvorky/gensim
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.0"
        },
        {
            "last_affected":  "4.0"
        },
        {
            "introduced":  "4.1"
        },
        {
            "last_affected":  "4.1"
        },
        {
            "introduced":  "4.2"
        },
        {
            "last_affected":  "4.2"
        },
        {
            "introduced":  "4.3"
        },
        {
            "last_affected":  "4.3"
        },
        {
            "introduced":  "4.4.0"
        },
        {
            "last_affected":  "4.4.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

4.*
4.0
4.0.0
4.0.1
4.1
4.1.0
4.1.1
4.1.2
4.2
4.2.0
4.3
4.3.0
4.3.1
4.3.2
4.3.3
4.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94091.json"