PT-2026-96012 · Pypi · Stable-Baselines3
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
stable-baselines3 versions prior to 2.9.1
Description
An issue exists in the
save util.py file involving unsafe pickle deserialization. This allows for remote attacks through the PPO.load(), load replay buffer(), and VecNormalize.load() functions. While a hardening measure using weights only=True for PyTorch tensor loading was introduced in version 2.9.0, it was subsequently reverted to maintain compatibility with PyTorch 1.13, leaving the core load APIs exploitable.Recommendations
Update stable-baselines3 to a version where PR #2264 has been implemented.
As a temporary workaround, restrict the use of
PPO.load(), load replay buffer(), and VecNormalize.load() when handling untrusted files.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stable-Baselines3