Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-63767: ktransformers Unauthenticated Command Execution via Pickle Payload
CVE-2026-63767
Summary
The ktransformers library, up to version 0.6.3, can be exploited by attackers to execute arbitrary commands on a server. This can happen when a malicious pickle payload is sent to the server, potentially allowing an attacker to access sensitive information or disrupt the system. To protect against this, update ktransformers to the latest version, which fixes this vulnerability.
Original title
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted ...
Original description
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell commands as the server process.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026