PT-2026-57625 · Unknown · Hashnerf-Pytorch

·

CVE-2026-15531

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions yashbhalgat HashNeRF-pytorch versions up to 82885e698295982504eb6a26d060a6b2473e3706
Description An issue exists in the Checkpoint File Handler component where the torch.load() function in the run nerf.py file is susceptible to deserialization. This occurs when the ckpt path argument is manipulated, allowing for potential code execution. This attack requires local access to the system.
Recommendations As a temporary workaround, avoid using the ckpt path argument in the run nerf.py file until the pending pull request is accepted and merged into the software.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15531

Affected Products

Hashnerf-Pytorch