CVE-2026-25873 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 18, 2026
OmniGen2-RL - Remote Code Execution
Overview
OmniGen2-RL contains a remote code execution caused by insecure pickle deserialization in the reward server component, letting unauthenticated remote attackers execute arbitrary commands via malicious HTTP POST requests.
Severity & Score
Impact
Unauthenticated remote attackers can execute arbitrary commands, potentially leading to full system compromise.
Mitigation
Update to the latest version with secure deserialization fixes.
References
- https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_server.py#L118
- https://github.com/VectorSpaceLab/OmniGen2/pull/139
- https://www.vulncheck.com/advisories/omnigen2-rl-reward-server-unsafe-deserialization-rce
- https://arxiv.org/abs/2506.18871
- https://chocapikk.com/posts/2026/omnigen2-pickle-rce/
- https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L208
- https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L224
Social Media Activity(2 posts)
š“ CVE-2026-25873 - Critical (9.8) OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle de... š https://www.thehackerwire.com/vulnerability/CVE-2026-25873/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-25873 - Critical (9.8) OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle de... š https://www.thehackerwire.com/vulnerability/CVE-2026-25873/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-25873
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- insecure_deserialization
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-502
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H