PT-2026-96012 · Pypi · Stable-Baselines3

·

CVE-2026-94093

·

Published

2026-09-20

·

Updated

2026-09-21

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions stable-baselines3 versions prior to 2.9.1
Description An issue exists in the save util.py file involving unsafe pickle deserialization. This allows for remote attacks through the PPO.load(), load replay buffer(), and VecNormalize.load() functions. While a hardening measure using weights only=True for PyTorch tensor loading was introduced in version 2.9.0, it was subsequently reverted to maintain compatibility with PyTorch 1.13, leaving the core load APIs exploitable.
Recommendations Update stable-baselines3 to a version where PR #2264 has been implemented. As a temporary workaround, restrict the use of PPO.load(), load replay buffer(), and VecNormalize.load() when handling untrusted files.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94093

Affected Products

Stable-Baselines3