Deserialization of Untrusted DataWeakness · CWE-502

CVE-2026-31237

CRITICAL · 9.8 CVSS v3.1 Published 2026-05-12
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If the file is a pickle (.pkl) file, it is loaded using pandas.read_pickle() without any validation or security restrictions. This allows the deserialization of arbitrary Python objects via the unsafe pickle module. A remote attacker can exploit this by providing a maliciously crafted pickle file, leading to arbitrary code execution on the system running the Ludwig prediction.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

The Ludwig framework through version 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its predict() method. When a user provides a dataset file path, the framework auto-detects the file format and uses pandas.read_pickle() to load .pkl files without validation, allowing arbitrary code execution via malicious pickle files.

MitigationReplace unsafe pandas.read_pickle() calls with safe deserialization methods (e.g., joblib, or implement validation/allowlisting) or explicitly block pickle file loading in the predict() method for untrusted inputs.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check installed Ludwig version
    Run 'pip show ludwig' or 'python -c "import ludwig; print(ludwig.__version__)"' to get the version number
    Affected if Version is 0.10.4 or lower (any version through 0.10.4)
  2. Identify use of predict() method with file paths
    Search codebases for calls to ludwig.predict() or the Ludwig AI predict API that accept dataset file paths as input
    Affected if The predict() method is invoked with a file path argument pointing to user-controlled data
  3. Verify .pkl file format auto-detection is active
    Inspect the Ludwig predict() code path to confirm it auto-detects file formats and can load .pkl files via pandas.read_pickle()
    Affected if The framework automatically processes .pkl files without validation when passed to predict()
  4. Confirm no pickle validation in deserialization pipeline
    Review custom code or Ludwig configuration for any input validation, allowlisting, or safe deserialization (e.g., joblib) applied before pandas.read_pickle() is called
    Affected if No validation exists and pandas.read_pickle() is called directly on untrusted .pkl input

You are affected if you run Ludwig <= 0.10.4 and use the predict() method with .pkl dataset files from untrusted sources without validation or safe deserialization in place.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

From vendor data
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Replace unsafe pandas.read_pickle() calls with safe deserialization methods (e.g., joblib, or implement validation/allowlisting) or explicitly block pickle file loading in the predict() method for untrusted inputs.

Have this fixed Scoped from the published advisory
  • Consultation6.0 h
  • Implementation12.0 h
  • Testing6.0 h
  • Review / QA4.0 h
28.0 hours of engineering $4,980
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $7,968.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-31237 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-31237 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data