Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days