PatchSiren

piskvorky CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW piskvorky CVE published 2026-09-20

CVE-2026-94091

A weakness in piskvorky gensim up to 4.4.0 allows for deserialization when loading a model. This issue, located in the `Load` function of `gensim/utils.py`, can be exploited remotely. The exploit has been made public, but there is no immediate fix or patch available as the maintainer closed the related issue without providing a solution. The vulnerability can be triggered by loading a malicious model, whi [truncated]