Local Assertion Vulnerability in ggml-org's Whisper.cpp
CVE-2026-17513

4.8MEDIUM

Key Information:

Vendor

Ggml-org

Vendor
CVE Published:
27 July 2026

What is CVE-2026-17513?

A locally exploitable assertion vulnerability exists in the ggml-ftype_to_ggml_type function of ggml-org's Whisper.cpp. This issue arises from manipulation of the function's argument, leading to a reachable assertion condition. Users should be aware that exploitation requires local access. Despite being reported early through an issue tracking system, the vendor has not yet responded to the concern, leaving potential risks unaddressed.

Affected Version(s)

whisper.cpp 95ea8f9b

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

m00dy (VulDB User)
VulDB CNA Team
.