Skip to content
ms-swiftGHSA-prfw-69r3-wqxf

ms-swift: Image Cache Hash Collision via Missing Dimension Metadata

Low3.6CVE-2026-10801 · Published Jun 4, 2026 · updated Jul 23, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
ms-swift
PyPI
<= 4.2.0No fix yet
Details and references

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-327
Also known as
CVE-2026-10801, PYSEC-2026-3488

More ms-swift advisories

All
DateAdvisory
Jul 312025MS SWIFT Deserialization RCE Vulnerability
GHSA-r54c-2xmf-2cf3Mediumno fix yet
Jul 312025MS SWIFT WEB-UI RCE Vulnerability
CVE-2025-41419Mediumfixed in 3.7.0
Jul 312025MS SWIFT Remote Code Execution via unsafe PyYAML deserialization
CVE-2025-50460Low9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.