CVE-2026-94091 | piskvorky gensim up to 4.4.0 Model Loader gensim/utils.py load fname deserialization (Issue 3663)
A vulnerability has been found in piskvorky gensim up to 4.4.0 and classified as problematic. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization.
The identification of this vulnerability is CVE-2026-94091. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Maintainer closed #3663 same-day with no comment, PR, or fix; repo’s last push (2025-11-01) predates the report, so the unsafe pickle.load in SaveLoad.load remains unguarded at develop HEAD.VulDB Recent EntriesRead More