CVE 9.8 CRITICAL

CVE-2026-31226_CVE-2026-31226

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerability arises from the unsafe construction and execution of shell commands via os.system() without proper input sanitization or escaping. User-controlled input (such as file paths) is directly interpolated into shell command strings using f-strings within the _copy() function. An attacker can inject arbitrary OS commands by supplying a specially crafted path parameter through the Hydra configuration framework. This leads to remote code execution with the privileges of the user running the TinyZero training process.

AI Analysis

Critical command injection vulnerability in TinyZero's HDFS file operation utilities, allowing remote code execution with user privileges.

Basic Information

ID CVE-2026-31226
Source mitre
Published May 12, 2026 at 00:00
Modified May 13, 2026 at 14:08

Affected Product

Vendor Jiayi-Pan
Product TinyZero
Version pre-commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Jiayi-Pan
Product TinyZero
Version pre-commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.