CVE-2026-10801
LOW SEVERITYCVSS Score & Metrics
Base Score
3.6 / 10
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Description
A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-327
Source
NVD
Vendor
modelscope
Product
ms-swift
External References
- https://github.com/modelscope/ms-swift/
- https://github.com/modelscope/ms-swift/issues/9360
- https://github.com/modelscope/ms-swift/pull/9359
- https://vuldb.com/cve/CVE-2026-10801
- https://vuldb.com/submit/831455
- https://vuldb.com/submit/831456
- https://vuldb.com/vuln/368250
- https://vuldb.com/vuln/368250/cti
Discussion (0)
Add Comment
No comments yet. Be the first!