Executive brief
Ludwig is an open-source framework used to build and deploy machine learning models. A security vulnerability in its model-serving component allows an attacker to execute malicious code on the server by providing a specially crafted model file. This could lead to a complete takeover of the system hosting the AI models and unauthorized access to sensitive data.
Technical details
Ludwig versions up to and including 0.10.4 are vulnerable to insecure deserialization (CWE-502) within the 'ludwig serve' command. The vulnerability exists because the framework utilizes the torch.load() function to load model weights without setting the 'weights_only=True' parameter. This allows the underlying pickle module to deserialize arbitrary Python objects. An attacker who can provide a maliciously crafted PyTorch model file to the server can achieve remote code execution (RCE) with the privileges of the Ludwig process. As of the advisory date, no patched version has been identified.
Affected products
- ludwig-ai Ludwig <= 0.10.4
Timeline
- 2026-05-12: advisory: GHSA-xp5q-5q7g-q26r published
- 2026-05-12: disclosed: CVE-2026-31238 published to NVD