CVE-2026-84452
Unauthenticated CORS API lets attackers set trust_remote_code=true, enabling RCE.
- CVSS 8.6
- 306
- Authentication, Authorization, and Session Management
- Remote
Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/build or /v1/cli/config and set the trust_remote_code parameter to true, which is converted to the –trust-remote-code command-line flag without validation. This reaches AutoConfig.from_pretrained with trust_remote_code=True in src/winml/modelkit/loader/_autoconfig.py and imports Python code from an attacker-controlled model repository, resulting in arbitrary code execution as the server user. This issue is fixed in version 0.4.0.
- CWE
- 306
- CVSS base score
- 8.6
- Published
- 2026-09-02
- OWASP
- A01 Broken Access Control
- Orthogonal defect classification
- Interface
- Code defect classification
- Incorrect Interface
- Category
- Authentication, Authorization, and Session Management
- Subcategory
- Insecure Authentication Mechanisms
- Accessibility scope
- Remote
- Impact
- Arbitrary Code Execution
- Affected component
- winml
- Fixed by upgrading
- Yes
Solution
Upgrade the package to version 0.4.0 or later.
Vulnerable code sample
import json
from flask import Flask, request, jsonify
from src.winml.modelkit.loader._autoconfig import AutoConfig
app = Flask(__name__)
# VULNERABLE: unrestricted CORS and no authentication
@app.after_request
def add_cors_headers(response):
response.headers['Access-Control-Allow-Origin'] = '*'
response.headers['Access-Control-Allow-Methods'] = 'POST,OPTIONS'
response.headers['Access-Control-Allow-Headers'] = 'Content-Type'
return response
@app.route('/v1/cli/build', methods=['POST'])
def cli_build():
data = request.get_json()
model_id = data.get('model_id')
trust_remote_code = data.get('trust_remote_code', False)
# Directly forward unvalidated flag to AutoConfig
config = AutoConfig.from_pretrained(model_id, trust_remote_code=trust_remote_code)
return jsonify({'status': 'ok', 'config': config.to_dict()})Patched code sample
import json
from flask import Flask, request, jsonify, abort
from src.winml.modelkit.loader._autoconfig import AutoConfig
app = Flask(__name__)
# FIX: restrict CORS origins and enforce simple token auth
ALLOWED_ORIGINS = {'https://trusted.example.com'}
API_TOKEN = 's3cr3t-token'
@app.after_request
def add_cors_headers(response):
origin = request.headers.get('Origin')
if origin in ALLOWED_ORIGINS:
response.headers['Access-Control-Allow-Origin'] = origin
response.headers['Access-Control-Allow-Methods'] = 'POST,OPTIONS'
response.headers['Access-Control-Allow-Headers'] = 'Content-Type,Authorization'
return response
def _require_auth():
auth = request.headers.get('Authorization')
if auth != f'Bearer {API_TOKEN}':
abort(401)
@app.route('/v1/cli/build', methods=['POST'])
def cli_build():
_require_auth()
data = request.get_json()
model_id = data.get('model_id')
# trust_remote_code must be explicitly false; ignore client value
config = AutoConfig.from_pretrained(model_id, trust_remote_code=False)
return jsonify({'status': 'ok', 'config': config.to_dict()})Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202684452,
title = {{Unauthenticated CORS API lets attackers set trust_remote_code=true, enabling RCE.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-84452},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-84452/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
