{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/onecompression-1.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-73325"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OneCompression (1.2.0)"],"_cs_severities":["high"],"_cs_tags":["deserialization","rce","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Fujitsu"],"content_html":"\u003cp\u003eFujitsu Research's OneCompression library version 1.2.0 contains a critical unsafe deserialization vulnerability, tracked as CVE-2026-73325. The flaw exists within the QuantizedModelLoader.load_quantized_model_pt() function, which unconditionally invokes the torch.load() method with the weights_only parameter set to False. By setting weights_only=False, the underlying PyTorch loader utilizes Python's pickle module for deserializing checkpoint files.\u003c/p\u003e\n\u003cp\u003eAn attacker can supply a maliciously crafted model.pt checkpoint file containing an embedded \u003cstrong\u003ereduce\u003c/strong\u003e method. When the library processes this file, it triggers the execution of the attacker's Python code within the context of the host process. This vulnerability allows for arbitrary command execution on systems leveraging this library to load model checkpoints, posing a high risk for machine learning pipelines or applications that ingest externally provided model files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to arbitrary code execution on systems running applications that utilize OneCompression version 1.2.0. This can result in full system compromise, data exfiltration, or persistence on the affected host. Any environment processing untrusted model files from external sources is at significant risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the OneCompression library to the latest version once a patch is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for all model checkpoint files to ensure they originate from trusted, verified sources.\u003c/li\u003e\n\u003cli\u003eMonitor application environments for the execution of unexpected processes originating from processes that utilize the OneCompression library.\u003c/li\u003e\n\u003cli\u003eAudit Python applications utilizing PyTorch to ensure torch.load() is used with weights_only=True whenever possible to mitigate deserialization risks globally.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T18:49:30Z","date_published":"2026-08-12T18:49:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fujitsu-onecompression-rce/","summary":"Fujitsu OneCompression library version 1.2.0 is vulnerable to arbitrary code execution via unsafe deserialization in the QuantizedModelLoader component.","title":"Arbitrary Code Execution in Fujitsu OneCompression Library","url":"https://feed.craftedsignal.io/briefs/2026-08-fujitsu-onecompression-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - OneCompression (1.2.0)","version":"https://jsonfeed.org/version/1.1"}