Deserialization Vulnerability in Comma AI Openpilot by Comma AI
CVE-2026-12191
8.5HIGH
What is CVE-2026-12191?
A deserialization vulnerability was identified in Comma AI Openpilot 0.11, specifically in the function pickle.load/pickle.loads located in selfdrive/modeld/modeld.py. This vulnerability allows an attacker with local access to exploit the Pickle Module, potentially manipulating the application's behavior. The vendor was notified about this issue but has not provided any response regarding remediation.
Affected Version(s)
Openpilot 0.11
