← Back to search

CVE-2026-71281

8.8 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows an attacker to execute arbitrary code by loading malicious cache/covariance files, posing a significant security risk.
Exploitability
Exploitation requires access to the affected modules and knowledge of the file format, making it moderately difficult.
Blast radius
If exploited, the impact could be severe, potentially leading to full system compromise or data loss.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected LoRA-GA and CorDA initialization modules until a patch is available.
code-execfile-loadsecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.