CVE-2026-95928 MEDIUM

CVE-2026-95928: recommenders-team recommenders Dict Loading mind_iterator.py pickle.load deserialization

Vendor Recommenders-Team
Product recommenders
Weakness CWE-502 · Unsafe deserialization
Published September 23, 2026
Last update September 23, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation results in deserialization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

September 23, 2026 CVE published
September 23, 2026 Record updated

Related vulnerabilities

04Related CVE