SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15531

MEDIUM · CVSS 5.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability affects the Checkpoint File Handler in the HashNeRF-pytorch component, specifically within the `torch.load` function in `run_nerf.py`, where improper handling of the `ckpt_path` argument can lead to local deserialization attacks. This could allow an attacker to execute arbitrary code on the affected system. Organizations using this software, particularly those relying on its checkpointing functionality, should prioritize remediation, especially since the exploit has been publicly disclosed.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15531
Severity
MEDIUM
CVSS
5.3
EPSS
0.12%

Original NVD Description

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipulation of the argument ckpt_path leads to deserialization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The pull request to fix this issue awaits acceptance.