{"id":"CVE-2026-47117","aliases":["GHSA-m3v4-v5gx-7wf5","PYSEC-2026-2852"],"title":"OpenMed vulnerable to remote code injection through privacy-filter model loading path","summary":"OpenMed vulnerable to remote code injection through privacy-filter model loading path","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"openmed","product":"openmed","ecosystem":"pip","affected":["openmed < 1.5.2"],"patched":["openmed 1.5.2"],"published":"2026-06-02","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-m3v4-v5gx-7wf5","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47117"},{"url":"https://github.com/maziyarpanahi/openmed/pull/59"},{"url":"https://github.com/maziyarpanahi/openmed/commit/98724f65df98d7518b9006e6356740aa36c2f224"},{"url":"https://github.com/maziyarpanahi/openmed/releases/tag/v1.5.2"},{"url":"https://www.vulncheck.com/advisories/openmed-remote-code-execution-via-pii-model-loading"},{"url":"github.com/maziyarpanahi/openmed"}],"tags":["osv","pip","exploit-available"],"epss":0.00915,"epssPercentile":0.58651,"ingestedAt":"2026-07-13T18:58:00.213Z","exploits":{"github":1,"githubRepos":["https://github.com/SaiTeja-Erukude/CVE-2026-47117-openmed-rce"],"checkedAt":"2026-09-24T07:53:04.462Z"},"exploitAvailable":true,"slug":"CVE-2026-47117","body":"## Overview\n\nOpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied `model_name` parameter, allowing a value such as `attacker/foo-privacy-filter-bar` to route through a path that loads Hugging Face models with `trust_remote_code=True`. An unauthenticated attacker can supply a malicious model repository containing custom Transformers code via auto_map in `config.json` or `tokenizer_config.json`, which is imported and executed with the privileges of the OpenMed service process.\n\n## Affected packages\n\n- `openmed < 1.5.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `openmed 1.5.2`","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5263,"id":"CVE-2026-47117","ts":1788887257343,"field":"exploit_available","old":"false","new":"true"},{"seq":4146,"id":"CVE-2026-47117","ts":1788886373779,"field":"exploit_available","old":"true","new":"false"},{"seq":2915,"id":"CVE-2026-47117","ts":1788883039654,"field":"exploit_available","old":"false","new":"true"},{"seq":1944,"id":"CVE-2026-47117","ts":1788882442695,"field":"exploit_available","old":"true","new":"false"},{"seq":1032,"id":"CVE-2026-47117","ts":1788881877645,"field":"exploit_available","old":"false","new":"true"}]}