CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

Amazon Web Services Version 1 original current

Imported from official source

Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. The issue arises whenever a user calls Predictor.deserialize() or any RepresentablePredictor.deserialize() on a model directory they do not fully control. Impacted versions: <0.17.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. View article

This version

Version
1 of 1
Recorded
September 29, 2026 16:00
Change
Initial
Content hash
79e32fdfd744ad5522c8e717943ab80b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.