Junglewise Threat Intelligence

CVE-2026-31239: State Spaces Mamba insecure deserialization in from_pretrained

CVE-2026-31239 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Vendors: PyPI.

Executive brief

Mamba is a software framework used for building and running advanced artificial intelligence language models. A security flaw allows attackers to execute malicious code on a user's computer if the user downloads and loads a compromised AI model from a public repository like HuggingFace Hub. This could lead to a full system takeover, data theft, or unauthorized access to the user's environment.

Technical details

The Mamba framework (mamba-ssm) up to version 2.2.6 is vulnerable to insecure deserialization (CWE-502) within the MambaLMHeadModel.from_pretrained() method. This occurs because the framework utilizes torch.load() to process 'pytorch_model.bin' weight files without setting the 'weights_only=True' parameter, defaulting to the unsafe pickle module. An attacker can exploit this by uploading a crafted model to the HuggingFace Hub; when a victim attempts to load this model, arbitrary Python objects are deserialized, resulting in remote code execution in the context of the Mamba process. No authentication is required to host a malicious model on public hubs, and the attack is triggered upon the victim's initiation of the model download and load process.

Affected products

  • state-spaces mamba-ssm <= 2.2.6

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: GitHub Advisory published

References