CVE-2026-15531: Deserialization in yashbhalgat HashNeRF-pytorch
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to deserialization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The pull request to fix this issue awaits acceptance.
AI Analysis
Technical Summary
CVE-2026-15531 describes a deserialization vulnerability in the HashNeRF-pytorch project by yashbhalgat. The issue is located in the Checkpoint File Handler component, specifically in the torch.load function within run_nerf.py. Manipulating the ckpt_path argument can lead to unsafe deserialization. Exploitation requires local access, and no user interaction is needed. The product follows a rolling release model, so no fixed or affected versions are explicitly stated. A patch is pending acceptance, and no official remediation is currently available.
Potential Impact
An attacker with local access can manipulate the checkpoint file path to cause unsafe deserialization, potentially leading to arbitrary code execution or other impacts associated with deserialization vulnerabilities. The CVSS 4.8 score indicates a medium severity impact with low attack complexity and no user interaction required. However, the attack vector is local, limiting remote exploitation.
Mitigation Recommendations
No official fix or patch is currently available as the pull request to address this vulnerability is awaiting acceptance. Users should monitor the vendor's repository for the acceptance of the fix and apply updates promptly once available. Until then, restrict local access to trusted users only and avoid loading checkpoint files from untrusted sources.
CVE-2026-15531: Deserialization in yashbhalgat HashNeRF-pytorch
Description
A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to deserialization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The pull request to fix this issue awaits acceptance.
CVSS v4.0
Score 4.8medium
Affected software
cpe:2.3:a:yashbhalgat:hashnerf-pytorch:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15531 describes a deserialization vulnerability in the HashNeRF-pytorch project by yashbhalgat. The issue is located in the Checkpoint File Handler component, specifically in the torch.load function within run_nerf.py. Manipulating the ckpt_path argument can lead to unsafe deserialization. Exploitation requires local access, and no user interaction is needed. The product follows a rolling release model, so no fixed or affected versions are explicitly stated. A patch is pending acceptance, and no official remediation is currently available.
Potential Impact
An attacker with local access can manipulate the checkpoint file path to cause unsafe deserialization, potentially leading to arbitrary code execution or other impacts associated with deserialization vulnerabilities. The CVSS 4.8 score indicates a medium severity impact with low attack complexity and no user interaction required. However, the attack vector is local, limiting remote exploitation.
Mitigation Recommendations
No official fix or patch is currently available as the pull request to address this vulnerability is awaiting acceptance. Users should monitor the vendor's repository for the acceptance of the fix and apply updates promptly once available. Until then, restrict local access to trusted users only and avoid loading checkpoint files from untrusted sources.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-12T15:56:12.103Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a54750d68715ace433701cd
Added to database: 07/13/2026, 05:18:05 UTC
Last enriched: 07/13/2026, 05:32:48 UTC
Last updated: 08/23/2026, 22:52:08 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.