Security Advisory

CVE-2026-3071

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-02-26 14:56:39
Last updated 2026-02-27 16:21:29
Assigner HiddenLayer
CVSS score 8.4
State PUBLISHED

Description

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.