Executive brief
Mamba is a software framework used for building and running advanced artificial intelligence language models. A security flaw allows attackers to execute malicious code on a user's computer if the user downloads and loads a compromised AI model from a public repository like HuggingFace Hub. This could lead to a full system takeover, data theft, or unauthorized access to the user's environment.
Technical details
The Mamba framework (mamba-ssm) up to version 2.2.6 is vulnerable to insecure deserialization (CWE-502) within the MambaLMHeadModel.from_pretrained() method. This occurs because the framework utilizes torch.load() to process 'pytorch_model.bin' weight files without setting the 'weights_only=True' parameter, defaulting to the unsafe pickle module. An attacker can exploit this by uploading a crafted model to the HuggingFace Hub; when a victim attempts to load this model, arbitrary Python objects are deserialized, resulting in remote code execution in the context of the Mamba process. No authentication is required to host a malicious model on public hubs, and the attack is triggered upon the victim's initiation of the model download and load process.
Affected products
- state-spaces mamba-ssm <= 2.2.6
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: GitHub Advisory published