Weak Hash Vulnerability in Modelscope's MS-Swift Product
CVE-2026-10801
Key Information:
- Vendor
Modelscope
- Status
- Vendor
- CVE Published:
- 4 June 2026
Badges
What is CVE-2026-10801?
A security vulnerability has been identified in Models' MS-Swift up to version 4.2.0. This issue revolves around the function Template._save_pil_image located in the swift/template/base.py file, where manipulation can lead to the use of weak hashing algorithms. While the attack is expected to be approached locally, it requires a high degree of complexity to exploit. The potential impact has been publicly disclosed, and the corresponding pull request to rectify this vulnerability is currently awaiting acceptance.
Affected Version(s)
ms-swift 4.0
ms-swift 4.1
ms-swift 4.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
