ms-swiftGHSA-prfw-69r3-wqxf
ms-swift: Image Cache Hash Collision via Missing Dimension Metadata
Low3.6CVE-2026-10801 · Published Jun 4, 2026 · updated Jul 23, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ms-swift PyPI | <= 4.2.0 | No fix yet |
Details and references
A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-327
- Also known as
- CVE-2026-10801, PYSEC-2026-3488
- nvd.nist.gov/vuln/detail/CVE-2026-10801
- github.com/modelscope/ms-swift/issues/9360
- github.com/modelscope/ms-swift/pull/9359
- github.com/modelscope/ms-swift/commit/27426a6431759a82e2a1c98344b425f90be17e07
- github.com/modelscope/ms-swift
- vuldb.com/cve/CVE-2026-10801
- vuldb.com/submit/831455
- vuldb.com/submit/831456
- vuldb.com/vuln/368250
- vuldb.com/vuln/368250/cti
More ms-swift advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 312025 | MS SWIFT Deserialization RCE Vulnerability GHSA-r54c-2xmf-2cf3Mediumno fix yet | Medium | No fix yet |
| Jul 312025 | MS SWIFT WEB-UI RCE Vulnerability CVE-2025-41419Mediumfixed in 3.7.0 | Medium | 3.7.0 |
| Jul 312025 | MS SWIFT Remote Code Execution via unsafe PyYAML deserialization CVE-2025-50460Low9.8no fix yet | Low9.8 | No fix yet |