{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/espnet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:espnet_project:espnet:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-90777"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ESPnet (\u003c 202609)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ESPnet"],"content_html":"\u003cp\u003eESPnet versions prior to 202609 contain a critical vulnerability in the handling of pretrained model checkpoints. The software utilizes the Python 'torch.load' function with the 'weights_only' parameter set to 'False'. By design, 'torch.load' relies on Python's 'pickle' module for deserialization. When 'weights_only' is disabled, the pickle process can instantiate arbitrary objects and execute embedded code within the checkpoint file. An attacker can create a weaponized checkpoint file and trick a user or system into loading it during the initialization or fine-tuning process of an ESPnet model. This flaw allows an attacker to achieve remote code execution in the context of the user or process running the ESPnet toolkit, potentially leading to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on systems running ESPnet. Given the nature of machine learning workflows, this poses a risk to research environments, data processing pipelines, and production inference systems where untrusted model checkpoints may be ingested. If exploited, an attacker could gain persistent access, exfiltrate sensitive model data, or pivot within the host network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of ESPnet to version 202609 or later immediately to address the insecure deserialization flaw.\u003c/li\u003e\n\u003cli\u003eImplement strict validation and provenance checks for all pretrained model checkpoints before loading them into the ESPnet framework.\u003c/li\u003e\n\u003cli\u003eExecute machine learning model processing within isolated containers or restricted environments to minimize the impact of potential command execution.\u003c/li\u003e\n\u003cli\u003eMonitor the Python process execution logs for unexpected child processes spawned by model initialization scripts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T13:25:41Z","date_published":"2026-09-13T13:25:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-espnet-rce/","summary":"ESPnet versions prior to 202609 are vulnerable to arbitrary code execution due to the insecure deserialization of pretrained model checkpoints using torch.load with weights_only=False.","title":"Arbitrary Code Execution in ESPnet via Insecure Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-09-espnet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - ESPnet","version":"https://jsonfeed.org/version/1.1"}