OpenMed versions before 1.5.2 contain a critical remote code execution flaw, tracked as CVE-2026-47117, in the PII privacy-filter model loading path. The vulnerability is caused by broad substring matching on the user-controlled model_name parameter, which can misroute attacker-supplied values into a Hugging Face loading path with trust_remote_code=True. An unauthenticated attacker can point OpenMed to a malicious model repository that defines custom Transformers code through auto_map in config.json or tokenizer_config.json, causing that code to be imported and executed with the privileges of the OpenMed service process.
The OpenMed project released version 1.5.2 to fix the issue by separating model routing from trust decisions, making trust_remote_code default to False in PrivacyFilterTorchPipeline, and limiting trusted remote-code loading to an explicit allowlist of first-party or operator-approved repositories. The release also introduced the OPENMED_TRUSTED_REMOTE_CODE_MODELS environment variable for controlled private fine-tunes, while pull request #59 added stricter identifier matching, gated remote-code dispatch, and security regression tests. The CVE is classified as CWE-94 and carries a critical CVSS 3.1 score with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-02, a CVE entry and advisory documented a critical remote code execution vulnerability in OpenMed versions before 1.5.2. The flaw stems from broad substring matching on a user-controlled model_name value that can route attacker-supplied Hugging Face repositories into a trust_remote_code-enabled loading path.
The CVE record states that disclosure for CVE-2026-47117 was received by disclosure@vulncheck.com on 2026-06-02. The issue affects OpenMed versions before 1.5.2 and allows unauthenticated remote code execution through the PII privacy-filter model loading path.
On 2026-05-27, OpenMed released version 1.5.2 as a security-focused update addressing a trust-boundary weakness in the privacy-filter model-loading path. The release separated model routing from trust decisions, defaulted trust_remote_code to false, and limited trusted remote-code loading to an explicit allowlist or operator-approved models.
On 2026-05-27, pull request #59 was merged into the OpenMed master branch after 13 checks passed. The changes restricted identifier matching, gated remote-code dispatch, added security regression tests, and documented the security hardening for version 1.5.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.