Arbitrary Code Injection Affecting openmed package, versions [,1.5.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.92% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary Code Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-OPENMED-17751097
  • published1 Jul 2026
  • disclosed2 Jun 2026
  • creditUnknown

Introduced: 2 Jun 2026

CVE-2026-47117  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade openmed to version 1.5.2 or higher.

Overview

openmed is an OpenMed delivers state-of-the-art biomedical and clinical LLMs that rival proprietary enterprise stacks, unifying model discovery, advanced extractions, and one-line orchestration.

Affected versions of this package are vulnerable to Arbitrary Code Injection via the model_name parameter in the privacy-filter dispatcher. An attacker can execute arbitrary code by supplying a malicious model repository that contains custom Transformers code, which is imported and run with the privileges of the service process.

CVSS Base Scores

version 4.0
version 3.1