CVE-2026-63767
ktransformers 0.6.3 and earlier contain a flaw that lets anyone send a crafted pickle to the SchedulerServer ZMQ socket and run arbitrary commands on the host. The vulnerability is triggered by deserializing malicious data and is not limited to authenticated users.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
ktransformers library, versions up to and including 0.6.3, used in applications that expose the SchedulerServer ZMQ ROUTER socket.
Real-world impact
An attacker can run any shell command on the machine where the SchedulerServer is running, potentially taking full control of the system.
Why this severity
The CVSS score of 9.3 reflects the lack of authentication, the high impact on confidentiality, integrity, and availability, and the ability to execute arbitrary code remotely.
What to do about it
- 01Upgrade ktransformers to a version that includes commit def0f93 or later.
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.