An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.
References
Configurations
No configuration.
History
01 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-502 |
01 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 17:16
Updated : 2026-06-01 21:16
NVD link : CVE-2026-38950
Mitre link : CVE-2026-38950
CVE.ORG link : CVE-2026-38950
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
