CVE-2026-84452 | Microsoft winml-cli up to 0.3.x CLI API _autoconfig.py AutoConfig.from_pretrained trust_remote_code cross-domain policy

SecurityVulns

A vulnerability classified as problematic was found in Microsoft winml-cli up to 0.3.x. This impacts the function AutoConfig.from_pretrained of the file src/winml/modelkit/loader/_autoconfig.py of the component CLI API. The manipulation of the argument trust_remote_code results in permissive cross-domain policy with untrusted domains.

This vulnerability is identified as CVE-2026-84452. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More