CVE-2026-108943 | ModelTC LightX2V up to 0.5.0 Tokenizer cosmos3_runner.py AutoTokenizer.from_pretrained auto_map code injection (Issue 1559)
A vulnerability, which was classified as problematic, has been found in ModelTC LightX2V up to 0.5.0. Affected is the function AutoTokenizer.from_pretrained of the file lightx2v/models/runners/cosmos3/cosmos3_runner.py of the component Tokenizer. This manipulation of the argument auto_map causes code injection.
This vulnerability is tracked as CVE-2026-108943. The attack is restricted to local execution. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More