{"id":"GHSA-m3v4-v5gx-7wf5","summary":"OpenMed vulnerable to remote code injection through privacy-filter model loading path","details":"OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied `model_name` parameter, allowing a value such as `attacker/foo-privacy-filter-bar` to route through a path that loads Hugging Face models with `trust_remote_code=True`. An unauthenticated attacker can supply a malicious model repository containing custom Transformers code via auto_map in `config.json` or `tokenizer_config.json`, which is imported and executed with the privileges of the OpenMed service process.","aliases":["CVE-2026-47117","PYSEC-2026-2852"],"modified":"2026-07-13T16:43:30.876937992Z","published":"2026-06-02T18:31:33Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-06-30T21:42:32Z","nvd_published_at":"2026-06-02T16:16:43Z","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47117"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/pull/59"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/commit/98724f65df98d7518b9006e6356740aa36c2f224"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/releases/tag/v1.5.2"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/openmed-remote-code-execution-via-pii-model-loading"},{"type":"PACKAGE","url":"github.com/maziyarpanahi/openmed"}],"affected":[{"package":{"name":"openmed","ecosystem":"PyPI","purl":"pkg:pypi/openmed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.2"}]}],"versions":["0.1","0.1.1","0.1.10","0.1.10rc1","0.1.4","0.1.5","0.1.7","0.1.8","0.1.8rc0","0.1.8rc2","0.1.9","0.1.9rc1","0.2.0","0.2.0rc1","0.2.0rc2","0.2.1","0.2.2","0.3.0","0.4.0","0.5.0","0.5.1","0.5.5","0.5.6","0.5.7","0.5.8","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-m3v4-v5gx-7wf5/GHSA-m3v4-v5gx-7wf5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}