{"id":"CVE-2026-73325","summary":"Fujitsu OneCompression \u003c 1.2.1 Arbitrary Code Execution via torch.load Deserialization","details":"Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce__ methods in a crafted model checkpoint to execute arbitrary Python code, including system commands, when the library loads the file from a caller-selected model directory.","modified":"2026-08-27T11:47:45.721936157Z","published":"2026-08-12T15:35:51.299Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"1.2.1"}]},{"extracted_events":[{"fixed":"1.2.1"}],"source":"DESCRIPTION"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73325.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73325.json"},{"type":"ADVISORY","url":"https://github.com/FujitsuResearch/OneCompression/blob/main/SECURITY.md"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73325"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/fujitsu-onecompression-arbitrary-code-execution-via-torch-load-deserialization"},{"type":"FIX","url":"https://pypi.org/project/onecomp/1.2.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/onecomp/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fujitsuresearch/onecompression","events":[{"introduced":"0"},{"fixed":"70e89052a6b2c85a611185fa774880523c05e8ca"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.2.1"}],"source":"DESCRIPTION"}}],"versions":["v1.2.0","v1.1.1","v1.1.0","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73325.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}