CVE-2026-12191 - CERT CVE
ID CVE-2026-12191
Sažetak A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.
Reference
CVSS
Base: 6.8
Impact: 10.0
Exploitability:3.1
Pristup
VektorSloženostAutentikacija
LOCAL LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:L/AC:L/Au:S/C:C/I:C/A:C
Zadnje važnije ažuriranje 14-06-2026 - 23:16
Objavljeno 14-06-2026 - 23:16