Impact
A deserialization vulnerability exists in tile-lang's KernelCache._load_kernel_from_disk function, allowing an attacker to manipulate serialized data that is read from disk. Exploiting this flaw could enable remote execution of arbitrary code or other malicious actions depending on how the deserialized objects are used by the application. The flaw is rooted in improper input validation and insecure deserialization practices.
Affected Systems
The vulnerability affects versions of tile-ai tilelang up to 0.1.14. No other vendors or products are mentioned. Users running 0.1.14 or earlier are at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the flaw is not listed in CISA's KEV catalog, which suggests limited known exploitation attempts so far. However, the description confirms that the attack can be performed from remote, so an attacker who can influence the data stored for the kernel cache could trigger the vulnerable deserialization path. Given the medium CVSS score and lack of active exploitation evidence, organizations should treat this as an important but not urgent issue, applying the vendor patch as soon as it is released.
OpenCVE Enrichment