Executive brief
A security vulnerability exists in Comma AI Openpilot, an open-source driver assistance system. The software incorrectly handles certain data files, which could allow an individual with local access to the device to execute unauthorized commands. This could lead to a complete takeover of the system, potentially impacting the safety and operational integrity of the vehicle's assistance features.
Technical details
An insecure deserialization vulnerability exists in Comma AI Openpilot 0.11 within the 'modeld' component. The issue is located in the file 'selfdrive/modeld/modeld.py' due to the unsafe use of 'pickle.load' and 'pickle.loads' functions. A local attacker with low privileges can exploit this by providing a specially crafted pickle object, leading to arbitrary code execution in the context of the application. As of the disclosure date, the vendor has not responded to reports of this vulnerability, and no official patch has been confirmed.
Affected products
- Comma AI Openpilot 0.11
Timeline
- 2026-06-14: disclosed: Vulnerability disclosed via VulDB/NVD
- 2026-06-14: advisory