Skip to content
ludwigGHSA-wcr3-gm9f-f87q

Ludwig framework is vulnerable to insecure deserialization through its predict() method

Critical9.8CVE-2026-31237 · Published May 12, 2026 · updated Jun 29, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If the file is a pickle (.pkl) file, it is loaded using pandas.read_pickle() without any validation or security restrictions. This allows the deserialization of arbitrary Python objects via the unsafe pickle module. A remote attacker can exploit this by providing a maliciously crafted pickle file, leading to arbitrary code execution on the system running the Ludwig prediction.

GitHub advisory

Affected versions

PackageAffectedFixed in
ludwig
PyPI
<= 0.10.4No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2026-31237, PYSEC-2026-404

More ludwig advisories

All ludwig
Advisory
Ludwig framework is vulnerable to insecure deserialization in its model serving component
Critical9.8May 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.