HIGH
CVHub520
CVE published 2026-08-25
CVE-2026-79785
CVE-2026-79785 debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T16:17:30.690Z and has not been modified since then. X-AnyLabeling's model downloader disables TLS certificate verification, allowing potential model substitution and arbitrary code execution. The model downloader built a context with ssl._create_unverified_context() and passed it to urllib.request.urlope [truncated]