CVE-2026-90777 UNKNOWN

CVE-2026-90777

Published: 2026-09-13

Description

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…