Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-31217

AI Predicted 9.8 Difficulty: Trivial EPSS 0.43% · P35

Possible ATT&CK Techniques 1AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProductVersion RangeStatus
n/an/an/aaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-31217

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user supplies a directory path via the --model command-line argument, the function reads a module.py file from that directory and executes its contents directly using Python's exec() function. This design does not validate or sanitize the file's content, allowing an attacker who controls the input directory to execute arbitrary Python code in the context of the process running the script.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
OptiMate 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OptiMate是Nebuly开源的一个AI模型优化工具库。 optimate存在安全漏洞,该漏洞源于neural_magic_training.py脚本中的_load_model()函数使用exec()直接执行用户提供的目录路径中的module.py文件内容,未验证或清理文件内容,允许攻击者控制输入目录执行任意Python代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2026-31217

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-31217

登录查看更多情报信息。

Security Blog Posts for CVE-2026-31217 (1)

Other References for CVE-2026-31217 (1)

Same Patch Batch · n/a · 2026-05-12 · 60 CVEs total

CVE-2026-20754Intel NPU Drivers 代码问题漏洞
CVE-2026-20714Intel QAT software drivers for Windows 缓冲区错误漏洞
CVE-2025-35991Intel Xeon Scalable Processors 安全漏洞
CVE-2025-35990Intel Endpoint Management Assistant 输入验证错误漏洞
CVE-2025-35979Intel Processors 安全漏洞
CVE-2025-36510Intel Display Virtualization for Windows OS driver 缓冲区错误漏洞
CVE-2026-20793Intel QAT software drivers for Windows 安全漏洞
CVE-2026-20782Intel QAT software drivers for Windows 安全漏洞
CVE-2026-20772Intel Connectivity Performance Suite 代码问题漏洞
CVE-2026-20771Intel QAT software drivers for Windows 代码问题漏洞
CVE-2026-20794Intel Data Center Graphics Driver 安全漏洞
CVE-2026-20753Intel Slim Bootloader 输入验证错误漏洞
CVE-2026-20751Intel Data Center Graphics Driver 缓冲区错误漏洞
CVE-2026-20738Intel QuickAssist Adapter 8960 安全漏洞
CVE-2026-20718Intel NPU Driver for Linux和Intel NPU Driver for Windows 安全漏洞
CVE-2026-20717Intel QAT software drivers for Windows 输入验证错误漏洞
CVE-2025-65719kubectl-mcp-server 安全漏洞
CVE-2025-70842FluentCMS 跨站脚本漏洞
CVE-2026-31222Snorkel 安全漏洞
CVE-2026-31239Mamba 安全漏洞

Showing top 20 of 60 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-31217

No comments yet


Leave a comment