CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization
Bulletin ID: 2026-119-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/29/2026 08:00 AM PDT
Description:
GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts.
Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with the privileges of the loading process via a crafted serialized model directory. The issue arises whenever a user calls Predictor.deserialize() or any RepresentablePredictor.deserialize() on a model directory they do not fully control.
Impacted versions: <0.17.0
Resolution:
This issue has been addressed in GluonTS version 0.17.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
We recommend users to only deserialize trusted model artifacts using the library.
References:
Acknowledgement:
We would like to thank Michael Holmquist (Hasp Labs) for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns..