PT-2026-57625 · Unknown · Hashnerf-Pytorch
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
yashbhalgat HashNeRF-pytorch versions up to 82885e698295982504eb6a26d060a6b2473e3706
Description
An issue exists in the Checkpoint File Handler component where the
torch.load() function in the run nerf.py file is susceptible to deserialization. This occurs when the ckpt path argument is manipulated, allowing for potential code execution. This attack requires local access to the system.Recommendations
As a temporary workaround, avoid using the
ckpt path argument in the run nerf.py file until the pending pull request is accepted and merged into the software.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashnerf-Pytorch