Junglewise Threat Intelligence

CVE-2026-31219: Nebuly AI Optimate insecure deserialization in neural_magic_training.py

CVE-2026-31219 · Severity: info · CVSS 7.8 · Published 2026-05-12

Technologies: Nebuly AI Optimate. Vendors: Nebuly AI.

Executive brief

Optimate is an open-source collection of libraries used to optimize the performance of AI models. A security vulnerability in its model-loading script allows for the execution of malicious code when a user attempts to load a specially crafted AI model file. This could lead to a complete compromise of the system running the software if an attacker convinces a user to process a malicious file.

Technical details

The _load_model() function in neural_magic_training.py is vulnerable to insecure deserialization (CWE-502) because it uses torch.load() without the weights_only=True parameter. When a user provides a path to a model file (such as .pt or .pth) via the --model command-line argument, the underlying Pickle module deserializes the file content. An attacker can craft a malicious model file containing arbitrary Python objects that execute code upon being unpickled. This vulnerability requires the victim to manually attempt to load the attacker's malicious model file.

Affected products

  • nebuly-ai optimate commit a6d302f912b481c94370811af6b11402f51d377f

Timeline

  • 2024-07-21: other: Vulnerable commit date
  • 2026-05-12: advisory: NVD publication date

References