PatchSiren

ModelCloud CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW ModelCloud CVE published 2026-09-07

CVE-2026-86288

A vulnerability was found in ModelCloud GPTQModel up to 7.2.0, affecting the Triton dequantization kernel in the file gptqmodel/nn_modules/qlinear/tritonv2.py. This issue allows for an out-of-bounds read due to manipulation of the argument g_idx, which can be exploited remotely. The exploit has been disclosed publicly. Upgrading to version 7.3.0 resolves this issue, with the patch being 877c732f7d7dccd56a [truncated]