CVE-2026-47117 is a remote code execution vulnerability affecting OpenMed before 1.5.2 in the PII privacy-filter model loading path. The flaw is caused by broad substring matching in the privacy-filter dispatcher on the user-controlled model_name parameter. Because identifiers merely containing the substring "privacy-filter" could be routed into the privacy-filter loading path, an attacker could supply a repository name such as attacker/foo-privacy-filter-bar and cause OpenMed to load it as a Hugging Face model with trust_remote_code=True. In that code path, attacker-controlled Transformers metadata in config.json or tokenizer_config.json, specifically auto_map entries, can cause custom Python code from the malicious repository to be imported and executed. The code runs with the privileges of the OpenMed service process. The issue is unauthenticated and network-reachable where the vulnerable model-loading functionality is exposed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working Python proof-of-concept for CVE-2026-47117, an unauthenticated RCE in OpenMed before 1.5.2. The exploit abuses user-controlled model_name values accepted by the PII API endpoints. Because vulnerable OpenMed logic treats identifiers containing 'privacy-filter' as trusted privacy-filter models and then loads Transformers artifacts with trust_remote_code=True, an attacker can supply a malicious Hugging Face-style model repository and achieve arbitrary Python execution during model/tokenizer import. Structure: the root contains documentation (README.md and exploit_walkthrough.md), dependency pinning (requirements.txt), a marker file showing expected proof output, and the main runner run_poc.py. The subdirectory foo-privacy-filter-bar is the malicious model fixture. Its config.json and tokenizer_config.json use auto_map to point Transformers at custom Python modules. configuration_poc.py defines a minimal config class, tokenization_poc.py and modeling_poc.py contain the import-time payload that writes proof strings to a marker file, and generate_bin.py creates a tiny pytorch_model.bin checkpoint so the model loads cleanly. Main exploit capability: run_poc.py imports the real OpenMed package, inspects routing helpers, sets OPENMED_POC_MARKER, creates a FastAPI TestClient for the OpenMed app, and sends a POST request to /pii/extract with model_name set to the local malicious model directory. Successful exploitation is determined by HTTP 200 plus creation of marker.txt containing lines from both malicious modules. The script also demonstrates that a Hub-style identifier attacker/foo-privacy-filter-bar would be classified as a privacy-filter model and routed to the torch backend, showing remote exploitability in real deployments. This is not merely a detector: it actively triggers the vulnerable code path and executes attacker-controlled Python, albeit with a harmless payload that writes a marker file. The PoC is operational but not heavily weaponized; the payload is fixed and intended for safe demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.