Home

Description

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

PUBLISHED Reserved 2026-02-23 | Published 2026-02-26 | Updated 2026-02-26 | Assigner HiddenLayer




HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-502 Deserialization of Untrusted Data

Product status

Default status
unaffected

0.4.1 (semver)
affected

References

www.hiddenlayer.com/sai-security-advisory/2026-02-flair

cve.org (CVE-2026-3071)

nvd.nist.gov (CVE-2026-3071)

Download JSON