Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file within the configured checkpoint path to trigger code execution during candidate discovery, even if the malicious checkpoint is never selected for recovery. | |
| Title | SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T19:36:57.357Z
Reserved: 2026-05-28T19:06:39.240Z
Link: CVE-2026-10036
No data.
Status : Received
Published: 2026-08-27T20:17:02.130
Modified: 2026-08-27T20:17:02.130
Link: CVE-2026-10036
No data.
OpenCVE Enrichment
Updated: 2026-08-28T05:45:04Z
-
CWE-502
Deserialization of Untrusted Data