Skip to content
ludwigGHSA-xp5q-5q7g-q26r

Ludwig framework is vulnerable to insecure deserialization in its model serving component

Critical9.8CVE-2026-31238 · Published May 12, 2026 · updated Jun 29, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files using torch.load() without enabling the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the pickle module. An attacker can exploit this by providing a maliciously crafted PyTorch model file, leading to arbitrary code execution on the system hosting the Ludwig model server.

GitHub advisory

Affected versions

PackageAffectedFixed in
ludwig
PyPI
<= 0.10.4No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2026-31238, PYSEC-2026-405

More ludwig advisories

All ludwig
Advisory
Ludwig framework is vulnerable to insecure deserialization through its predict() method
Critical9.8May 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.