Executive brief
Nebuly AI Optimate is a collection of libraries used to optimize the performance of AI models. A security vulnerability exists in how the software handles model files, allowing a malicious actor to execute unauthorized commands on a user's system. This occurs when the software processes a specially crafted model file, potentially leading to a full system compromise or data theft.
Technical details
The _load_model() function in neural_magic_training.py within the Optimate project (specifically commit a6d302f) is vulnerable to insecure deserialization (CWE-502). The vulnerability exists because the code calls torch.load() on a state_dict.pt file without setting the weights_only=True parameter. Since torch.load() uses the Python pickle module by default, it can be coerced into deserializing arbitrary Python objects. An attacker can exploit this by providing a maliciously crafted state_dict.pt file via the --model argument, resulting in arbitrary code execution with the privileges of the user running the script.
Affected products
- Nebuly AI optimate commit a6d302f912b481c94370811af6b11402f51d377f
Timeline
- 2024-07-21: other: Vulnerable commit date
- 2026-05-12: disclosed: NVD publication date