Sceawere
Vulnerability Detail
CVE-2026-100308UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Amazon GluonTS Deserialization Command Execution
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 9h ago
- Vendor
- AWS
- Product
- gluonts
- Attack Type
- CWE-502 Deserialization of untrusted data
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. To remediate this issue, users should upgrade to version 0.17.0 or later.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T16:17:04.900Z",
"pubdate": "2026-09-29T16:17:04.900Z",
"executiveSummary": "Amazon GluonTS versions prior to 0.17.0 are susceptible to a critical deserialization vulnerability within the model loading component. This flaw allows an unauthenticated or context-dependent attacker to trigger arbitrary operating system command execution by providing a maliciously crafted serialized model directory.\nThe vulnerability arises from insecure handling of untrusted data during the model reconstruction process. By injecting a payload into the serialized data, an attacker can manipulate the internal state of the loading function, leading to Remote Code Execution (RCE) with the security context of the process invoking the loader.\nThe primary risk implication is a total compromise of the application environment where model loading occurs. Given that model loading is a core function in machine learning workflows, this poses a significant threat to infrastructure integrity, data confidentiality, and system availability. Successful exploitation does not inherently require prior authentication, provided the attacker can influence the input directory used for model loading operations.",
"technicalDetails": "The vulnerability resides in the model loading subsystem of Amazon GluonTS, which improperly handles the deserialization of objects from stored model data. In many Python-based machine learning frameworks, serialized models are often stored using the pickle module or similar object-persistence mechanisms that inherently support arbitrary code execution if the input stream is not cryptographically signed or validated against a safe schema.\nThe root cause is the deserialization of untrusted data originating from a model directory. When the library processes a serialized file, it invokes routines that instantiate objects defined within the serialized payload. If an attacker constructs a malicious payload containing an __reduce__ method or similar gadget chains common to Python serialization vulnerabilities, the interpreter executes the attacker-defined commands as soon as the object is reconstructed.\nThe attack flow begins when the GluonTS loading component parses a model directory provided by an attacker. This directory contains serialized objects that have been specifically crafted to include a payload. As the library iterates through the files to restore the model state, it deserializes these malicious objects. Because the library lacks sufficient input validation or object allow-listing during this phase, the Python interpreter treats the embedded instructions as legitimate code.\nThe exploitation requirement is limited to the attacker's ability to influence the file path or content loaded by the GluonTS library. Once the vulnerable code triggers the deserialization process, the payload executes with the privileges of the system process running the GluonTS application. This effectively grants the attacker the ability to perform any action the process is permitted to execute, such as establishing a reverse shell, exfiltrating local environment variables, reading sensitive configuration files, or installing persistence mechanisms.\nThis vulnerability affects Amazon GluonTS versions prior to 0.17.0. The lack of sanitization in the model loading interface means that any pipeline accepting serialized model input from external, untrusted sources—such as user-uploaded model repositories or shared network drives—is inherently vulnerable to remote command injection."
}