{"id":"PYSEC-2026-2852","summary":"OpenMed vulnerable to remote code injection through privacy-filter model loading path","details":"OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied `model_name` parameter, allowing a value such as `attacker/foo-privacy-filter-bar` to route through a path that loads Hugging Face models with `trust_remote_code=True`. An unauthenticated attacker can supply a malicious model repository containing custom Transformers code via auto_map in `config.json` or `tokenizer_config.json`, which is imported and executed with the privileges of the OpenMed service process.","aliases":["CVE-2026-47117","GHSA-m3v4-v5gx-7wf5"],"modified":"2026-07-13T16:32:33.806674335Z","published":"2026-07-13T15:46:14.064755Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47117"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/pull/59"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/commit/98724f65df98d7518b9006e6356740aa36c2f224"},{"type":"WEB","url":"https://github.com/maziyarpanahi/openmed/releases/tag/v1.5.2"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/openmed-remote-code-execution-via-pii-model-loading"},{"type":"PACKAGE","url":"github.com/maziyarpanahi/openmed"},{"type":"PACKAGE","url":"https://pypi.org/project/openmed"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m3v4-v5gx-7wf5"}],"affected":[{"package":{"name":"openmed","ecosystem":"PyPI","purl":"pkg:pypi/openmed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.2"}]}],"versions":["0.1","0.1.1","0.1.10","0.1.10rc1","0.1.4","0.1.5","0.1.7","0.1.8","0.1.8rc0","0.1.8rc2","0.1.9","0.1.9rc1","0.2.0","0.2.0rc1","0.2.0rc2","0.2.1","0.2.2","0.3.0","0.4.0","0.5.0","0.5.1","0.5.5","0.5.6","0.5.7","0.5.8","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.5.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/openmed/PYSEC-2026-2852.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}