Executive brief
Flair is a popular natural language processing (NLP) framework used to train and deploy machine learning models for tasks like named entity recognition and sentiment analysis. Versions 0.15.0 and 0.15.1 contain a critical flaw in the model loading mechanism that allows attackers to execute arbitrary code by supplying a malicious model file. An attacker can exploit this to gain full system access with the privileges of the application running Flair.
Technical details
The vulnerability exists in flair/models/clustering.py, where the ClusteringModel.load static method unsafely deserializes model files using pickle.loads(joblib.load(str(model_file))). Although clustering support was documented as removed in version 0.15.0, the vulnerable module remains present in the distributed package and can be accessed via direct import (flair.models.clustering). The attack requires only that an attacker-controlled model file be loaded by a victim application, with no authentication or network prerequisites. Successful exploitation executes arbitrary Python code with the privileges of the loading process. The vulnerability is identical in root cause and sink to CVE-2024-10073, which incorrectly marked 0.15.0 as fixed due to the undocumented retention of the clustering module.
Affected products
- Flair Flair 0.15.0, 0.15.1
Timeline
- 2026-08-24: disclosed
- 2026-08-24: advisory