PT-2026-22736 · Unknown · Step-Video-T2V

CVE-2025-57622

·

Published

2026-03-03

·

Updated

2026-03-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Step-Video-T2V (affected versions not specified)
Description An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code. The issue is related to the /vae-api and /caption-api endpoints, specifically through the pickle.loads(request.get data()) component. The request.get data() function retrieves data sent by a client, and pickle.loads() deserializes this data. Deserializing untrusted data with pickle.loads() can lead to arbitrary code execution if the pickled data is maliciously crafted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57622

Affected Products

Step-Video-T2V