CVE-2026-100308
HIGH
NVD
CVSS Score
7.8
Severity
HIGH
Published
Sep 29, 2026
Vendor
unknown
Description
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. To remediate this issue, users should upgrade to version 0.17.0 or later.