PT-2026-61706 · Unknown · Transformers

·

CVE-2026-63767

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ktransformers versions prior to 0.6.3 commit def0f93
Description An unauthenticated pickle deserialization issue exists where remote attackers can execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. This is achieved by exploiting malicious reduce methods embedded in the payloads, allowing shell commands to be executed with the privileges of the server process. Pickle deserialization is the process of converting a byte stream back into a Python object, which can be dangerous if the data source is untrusted.
Recommendations Update ktransformers to the version containing commit def0f93.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63767

Affected Products

Transformers