Junglewise Threat Intelligence

CVE-2026-18285: Aeon load_rehab_pile_dataset deserialization RCE

CVE-2026-18285 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: Aeon. Vendors: Aeon.

Executive brief

Aeon is a time-series analysis toolkit used by data scientists and researchers for machine learning workflows. A deserialization vulnerability in the load_rehab_pile_dataset method allows attackers to execute arbitrary code on a user's machine when they open a malicious file or visit a specially crafted page, potentially compromising research data, system integrity, or enabling further network penetration.

Technical details

The vulnerability is a deserialization-of-untrusted-data flaw in Aeon's load_rehab_pile_dataset method, resulting from insufficient validation of user-supplied input. The attack vector is local with user interaction required—an attacker must trick a user into opening a malicious file or visiting a malicious page. The attack results in arbitrary code execution in the context of the current process. A patch is available via GitHub commit 751918052c0cce266b4f7cd4b084408526efc015.

Affected products

  • Aeon Aeon

Timeline

  • 2026-02-17: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public release of advisory
  • 2026-07-29: patched: Update issued; patch available at GitHub commit 751918052c0cce266b4f7cd4b084408526efc015

References

Related threats