PatchSiren

flairNLP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH flairNLP CVE published 2026-08-24

CVE-2026-76843

CVE-2026-76843 is a vulnerability in the Flair library, specifically in the ClusteringModel.load static method, which executes arbitrary Python while loading a model file. This issue is similar to CVE-2024-10073, but the earlier record's fixed version does not hold for the shipped package. The vulnerability allows an attacker to execute arbitrary Python code with the privileges of the loading process, imp [truncated]