Impact
The Load function in gensim/utils.py deserializes data from an argument named fname without performing input validation, permitting the injection of a malicious pickle object. When this function is invoked with crafted data, the pickle machinery executes arbitrary code, leading to potential compromise of confidentiality, integrity, and availability. The vulnerability is actionable remotely if an application exposes the parameter to external users; only a normal function call is required and an attacker can trigger the deserialization entirely through input manipulation. Maintaining the issue without a fix means the vulnerability remains present in all releases up to 4.4.0 and the current develop head.
Affected Systems
piskvorky gensim models up to version 4.4.0 are affected. No incremental versioning or hotfixes are documented for the issue, and the repository's last push precedes the publicly available exploit, indicating that the unsafe pickle.load call remains in the code base for all current releases.
Risk and Exploitability
The CVSS score of 5.1 indicates that the vulnerability is considered a moderate security risk; however, the EPSS score is not available, so the exact likelihood of exploitation cannot be determined. The vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that it is feasible to trigger remote code execution. Based on the description, the likely attack vector is remote – an attacker can influence the fname argument via a network interface or user‑provided input and subsequently cause the application to load a malicious pickle.
OpenCVE Enrichment