VYPR
High severity8.8NVD Advisory· Published Sep 13, 2026

CVE-2026-90777

CVE-2026-90777

Description

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Espnet/Espnetreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <202609

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.