{"id":"CVE-2026-31239","aliases":["PYSEC-2026-406"],"url":"https://o3.security/vulnerability/CVE-2026-31239","summary":"mamba language model framework vulnerable to insecure deserialization when loading pre-trained models from HuggingFace Hub","details":"The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_model.bin weight file without enabling the security-restrictive weights_only=True parameter. This allows the deserialization of arbitrary Python objects via the pickle module. An attacker can exploit this by publishing a malicious model repository on HuggingFace Hub. When a victim loads a model from this repository, arbitrary code is executed on the victim's system in the context of the mamba process.","published":"2026-05-12T18:30:41Z","modified":"2026-06-29T12:26:10.536535551Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00409,"percentile":0.33718,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mamba-ssm","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31239"},{"type":"PACKAGE","url":"https://github.com/state-spaces/mamba"},{"type":"WEB","url":"https://www.notion.so/CVE-2026-31239-35d1e1393188810d9baedfbd8363f396"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:10.536535551Z"}}