SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79785

MEDIUM · CVSS 5.9 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability arises from X-AnyLabeling's model downloader, which disables TLS certificate verification, allowing an attacker to intercept and replace model files during download without any validation of their authenticity. This could lead to the execution of malicious code during model inference, particularly affecting applications using ONNX or PyTorch formats. Organizations utilizing X-AnyLabeling for model management should prioritize addressing this vulnerability to mitigate the risk of executing compromised models.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79785
Severity
MEDIUM
CVSS
5.9
EPSS
0.18%

Original NVD Description

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain nor the hostname was checked on any model download, and models are fetched over HTTPS from the project's release host. Any party positioned to intercept that connection could therefore answer it with content of their own choosing. The response is written to a .part file and moved into place with os.replace, and the only post-download check, safe_check_model, validates the file's format rather than its provenance: no hash or signature is compared against an expected value. For an ONNX target the substituted file passes onnx.checker.check_model and is then used for inference, so the attacker chooses the model that produces the application's annotations. For a .pth or .pt target, which the shipped SAM2 video, YOLOE, UPN and open_vision configurations use, the check worker calls torch.load without weights_only, so a substituted file is unpickled and executes code of the attacker's choosing on PyTorch releases predating the weights_only default.