{"id":"CVE-2026-100308","title":"Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a craf…","summary":"Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a craf…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-470","CWE-502"],"vendor":"AWS","product":"gluonts","affected":["gluonts < 0.17.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:04.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100308","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-119-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/gluonts/releases/tag/v0.17.0","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/awslabs/gluonts/security/advisories/GHSA-64q6-5qv7-cwj9","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.262Z","slug":"CVE-2026-100308","body":"## Overview\n\nDeserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory.\n\n\n\nTo remediate this issue, users should upgrade to version 0.17.0 or later.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}