No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance. | |
| Title | modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash | |
| First Time appeared |
Modelscope
Modelscope ms-swift |
|
| Weaknesses | CWE-327 CWE-328 |
|
| CPEs | cpe:2.3:a:modelscope:ms-swift:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Modelscope
Modelscope ms-swift |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-04T11:00:13.074Z
Reserved: 2026-06-04T04:59:37.871Z
Link: CVE-2026-10801
No data.
Status : Received
Published: 2026-06-04T11:16:25.800
Modified: 2026-06-04T11:16:25.800
Link: CVE-2026-10801
No data.
OpenCVE Enrichment
No data.