Description
A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Maintainer closed #3663 same-day with no comment, PR, or fix; repo's last push (2025-11-01) predates the report, so the unsafe pickle.load in SaveLoad.load remains unguarded at develop HEAD.
Published: 2026-09-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The Load function in gensim/utils.py deserializes data from an argument named fname without performing input validation, permitting the injection of a malicious pickle object. When this function is invoked with crafted data, the pickle machinery executes arbitrary code, leading to potential compromise of confidentiality, integrity, and availability. The vulnerability is actionable remotely if an application exposes the parameter to external users; only a normal function call is required and an attacker can trigger the deserialization entirely through input manipulation. Maintaining the issue without a fix means the vulnerability remains present in all releases up to 4.4.0 and the current develop head.

Affected Systems

piskvorky gensim models up to version 4.4.0 are affected. No incremental versioning or hotfixes are documented for the issue, and the repository's last push precedes the publicly available exploit, indicating that the unsafe pickle.load call remains in the code base for all current releases.

Risk and Exploitability

The CVSS score of 5.1 indicates that the vulnerability is considered a moderate security risk; however, the EPSS score is not available, so the exact likelihood of exploitation cannot be determined. The vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that it is feasible to trigger remote code execution. Based on the description, the likely attack vector is remote – an attacker can influence the fname argument via a network interface or user‑provided input and subsequently cause the application to load a malicious pickle.

Generated by OpenCVE AI on September 20, 2026 at 23:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade gensim to a version that removes the unsafe pickle.load from the load function, if such a version becomes available
  • If an upgraded version is not yet released, refuse or sanitize the fname argument, ensuring that only files from a trusted source are passed to load()
  • Implement additional validation to confirm that the file being loaded is a legitimate gensim model and not a handcrafted pickle, and consider using safer deserialization mechanisms if available

Generated by OpenCVE AI on September 20, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Maintainer closed #3663 same-day with no comment, PR, or fix; repo's last push (2025-11-01) predates the report, so the unsafe pickle.load in SaveLoad.load remains unguarded at develop HEAD.
Title piskvorky gensim Model Loader utils.py load deserialization
First Time appeared Piskvorky
Piskvorky gensim
Weaknesses CWE-20
CWE-502
CPEs cpe:2.3:a:piskvorky:gensim:*:*:*:*:*:*:*:*
Vendors & Products Piskvorky
Piskvorky gensim
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Piskvorky Gensim
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T10:58:22.685Z

Reserved: 2026-09-20T08:31:39.843Z

Link: CVE-2026-94091

cve-icon Vulnrichment

Updated: 2026-09-21T10:58:17.394Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T23:17:02.977

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-94091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:00Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-502

    Deserialization of Untrusted Data