PT-2026-96010 · Pypi · Gensim

·

CVE-2026-94091

·

Published

2026-09-20

·

Updated

2026-09-21

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions piskvorky gensim versions prior to 4.4.1
Description A deserialization issue exists in the Model Loader component within the Load() function of the gensim/utils.py file. A remote attacker can trigger this by manipulating the fname argument, which leads to the unsafe use of pickle.load. Deserialization is the process of converting a data format (like a byte stream) back into an object, which can be dangerous if the input is untrusted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, avoid using the Load() function in gensim/utils.py with untrusted files.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94091

Affected Products

Gensim