<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:25:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-363540</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363540</link>
      <description>EUVD-2026-363540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363540</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84452</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84452</link>
      <description>&lt;p&gt;Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/build or /v1/cli/config and set the trust_remote_code parameter to true, which is converted to the --trust-remote-code command-line flag without validation. This reaches AutoConfig.from_pretrained with trust_remote_code=True in src/winml/modelkit/loader/_autoconfig.py and imports Python code from an attacker-controlled model repository, resulting in arbitrary code execution as the server user. This issue is fixed in version 0.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/build or /v1/cli/config and set the trust_remote_code parameter to true, which is converted to the --trust-remote-code command-line flag without validation. This reaches AutoConfig.from_pretrained with trust_remote_code=True in src/winml/modelkit/loader/_autoconfig.py and imports Python code from an attacker-controlled model repository, resulting in arbitrary code execution as the server user. This issue is fixed in version 0.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84452</guid>
    </item>
    <item>
      <title>GHSA-96p9-rh4f-92cf — Windows ML CLI: CORS misconfig enables localhost RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-96p9-rh4f-92cf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: winml-cli&lt;/p&gt;
&lt;p&gt;Case Description:&lt;/p&gt;
&lt;p&gt;MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the &amp;#39;serve/cli_api.py&amp;#39; component of the &amp;#39;winml-cli&amp;#39; project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets &amp;#39;allow_origins&amp;#39; to a wildcard, allowing any website to interact with the endpoint. This, combined with the &amp;#39;--trust-remote-code&amp;#39; flag in &amp;#39;build&amp;#39; and &amp;#39;config&amp;#39; commands, enables an attacker to execute arbitrary code by hosting a malicious model repository. The root cause is the lack of proper authentication and validation of the &amp;#39;trust_remote_code&amp;#39; parameter, leading to Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;Finder Description: WARNING: Original content contained invalid characters. Please see original submission in the event that the characters removed are relevant for the PoC.&lt;/p&gt;
&lt;p&gt;serve/cli_api.py exposes every winml CLI command over HTTP with no authentication. That&amp;#39;s defensible on its own - it binds 127.0.0.1 by default, so the audience is this machine. But it also sets allow_origins=[&amp;#34;*&amp;#34;] (cli_api.py:150, duplicated at app.py:219), and the victim&amp;#39;s browser is a local process: the wildcard lets any website call the endpoint and read the reply, erasing the boundary the loopback bind draws.&lt;/p&gt;
&lt;p&gt;build and config both accept --trust-remote-code, and a JSON true becomes that flag unfiltered. An attacker-named model repo reaches AutoConfig.from_pretrained(..., trust_remote_code=True) (_autoconfig.py:191), wher…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: winml-cli&lt;/p&gt;
&lt;p&gt;Case Description:&lt;/p&gt;
&lt;p&gt;MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the &amp;#39;serve/cli_api.py&amp;#39; component of the &amp;#39;winml-cli&amp;#39; project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets &amp;#39;allow_origins&amp;#39; to a wildcard, allowing any website to interact with the endpoint. This, combined with the &amp;#39;--trust-remote-code&amp;#39; flag in &amp;#39;build&amp;#39; and &amp;#39;config&amp;#39; commands, enables an attacker to execute arbitrary code by hosting a malicious model repository. The root cause is the lack of proper authentication and validation of the &amp;#39;trust_remote_code&amp;#39; parameter, leading to Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;Finder Description: WARNING: Original content contained invalid characters. Please see original submission in the event that the characters removed are relevant for the PoC.&lt;/p&gt;
&lt;p&gt;serve/cli_api.py exposes every winml CLI command over HTTP with no authentication. That&amp;#39;s defensible on its own - it binds 127.0.0.1 by default, so the audience is this machine. But it also sets allow_origins=[&amp;#34;*&amp;#34;] (cli_api.py:150, duplicated at app.py:219), and the victim&amp;#39;s browser is a local process: the wildcard lets any website call the endpoint and read the reply, erasing the boundary the loopback bind draws.&lt;/p&gt;
&lt;p&gt;build and config both accept --trust-remote-code, and a JSON true becomes that flag unfiltered. An attacker-named model repo reaches AutoConfig.from_pretrained(..., trust_remote_code=True) (_autoconfig.py:191), wher…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-96p9-rh4f-92cf</guid>
    </item>
    <item>
      <title>PYSEC-2026-3944 — Windows ML CLI: CORS misconfig enables localhost RCE</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3944</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: winml-cli&lt;/p&gt;
&lt;p&gt;Case Description:&lt;/p&gt;
&lt;p&gt;MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the &amp;#39;serve/cli_api.py&amp;#39; component of the &amp;#39;winml-cli&amp;#39; project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets &amp;#39;allow_origins&amp;#39; to a wildcard, allowing any website to interact with the endpoint. This, combined with the &amp;#39;--trust-remote-code&amp;#39; flag in &amp;#39;build&amp;#39; and &amp;#39;config&amp;#39; commands, enables an attacker to execute arbitrary code by hosting a malicious model repository. The root cause is the lack of proper authentication and validation of the &amp;#39;trust_remote_code&amp;#39; parameter, leading to Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;Finder Description: WARNING: Original content contained invalid characters. Please see original submission in the event that the characters removed are relevant for the PoC.&lt;/p&gt;
&lt;p&gt;serve/cli_api.py exposes every winml CLI command over HTTP with no authentication. That&amp;#39;s defensible on its own - it binds 127.0.0.1 by default, so the audience is this machine. But it also sets allow_origins=[&amp;#34;*&amp;#34;] (cli_api.py:150, duplicated at app.py:219), and the victim&amp;#39;s browser is a local process: the wildcard lets any website call the endpoint and read the reply, erasing the boundary the loopback bind draws.&lt;/p&gt;
&lt;p&gt;build and config both accept --trust-remote-code, and a JSON true becomes that flag unfiltered. An attacker-named model repo reaches AutoConfig.from_pretrained(..., trust_remote_code=True) (_autoconfig.py:191), wher…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: winml-cli&lt;/p&gt;
&lt;p&gt;Case Description:&lt;/p&gt;
&lt;p&gt;MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the &amp;#39;serve/cli_api.py&amp;#39; component of the &amp;#39;winml-cli&amp;#39; project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets &amp;#39;allow_origins&amp;#39; to a wildcard, allowing any website to interact with the endpoint. This, combined with the &amp;#39;--trust-remote-code&amp;#39; flag in &amp;#39;build&amp;#39; and &amp;#39;config&amp;#39; commands, enables an attacker to execute arbitrary code by hosting a malicious model repository. The root cause is the lack of proper authentication and validation of the &amp;#39;trust_remote_code&amp;#39; parameter, leading to Remote Code Execution (RCE).&lt;/p&gt;
&lt;p&gt;Finder Description: WARNING: Original content contained invalid characters. Please see original submission in the event that the characters removed are relevant for the PoC.&lt;/p&gt;
&lt;p&gt;serve/cli_api.py exposes every winml CLI command over HTTP with no authentication. That&amp;#39;s defensible on its own - it binds 127.0.0.1 by default, so the audience is this machine. But it also sets allow_origins=[&amp;#34;*&amp;#34;] (cli_api.py:150, duplicated at app.py:219), and the victim&amp;#39;s browser is a local process: the wildcard lets any website call the endpoint and read the reply, erasing the boundary the loopback bind draws.&lt;/p&gt;
&lt;p&gt;build and config both accept --trust-remote-code, and a JSON true becomes that flag unfiltered. An attacker-named model repo reaches AutoConfig.from_pretrained(..., trust_remote_code=True) (_autoconfig.py:191), wher…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3944</guid>
    </item>
  </channel>
</rss>
