Junglewise Threat Intelligence

CVE-2026-10801: ModelScope ms-swift Weak Hash in PIL Image Cache Key Handler

CVE-2026-10801 · Severity: low · CVSS 3.6 · Published 2026-06-04

Technologies: Modelscope Ms-Swift. Vendors: PyPI.

Executive brief

Modelscope ms-swift, a framework for fine-tuning large models, contains a flaw in how it caches images during training and inference. Because the software does not include image dimensions when creating a unique ID (hash) for cached images, two different images with the same raw data but different shapes can be confused for one another. This could lead to a model processing the wrong image, potentially causing incorrect results or data integrity issues during sensitive AI operations.

Technical details

A vulnerability exists in the `Template._save_pil_image` function within `swift/template/base.py` of modelscope ms-swift through version 4.2.0. The implementation uses `SHA256(image.tobytes())` to generate cache keys; however, the `tobytes()` method in the PIL library only returns flattened pixel data, excluding metadata such as width, height, and mode. An attacker with local access could potentially engineer images that result in hash collisions, causing the application to retrieve the wrong image from the cache. This impacts the integrity of multimodal inference and training. A fix involving the inclusion of image dimensions and mode in the hash input has been proposed in pull request #9359.

Affected products

  • modelscope ms-swift <= 4.2.0

Timeline

  • 2026-05-16: disclosed: Issue and pull request opened on GitHub
  • 2026-06-04: advisory: Published to GitHub Advisory Database and NVD

References

Related threats