Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization

A security vulnerability (CVE-2026-100308) was found in Amazon GluonTS, a library for deep learning models on time series data. It allows attackers to run any operating system commands if they load a manipulated model from an untrusted source. This can happen when users call deserialization functions on model directories they don't fully control.

QCS published 5/10/2026, 3:29:18 am ISTVendor disclosure 29/9/2026, 8:47:30 pm ISTVerified 5/10/2026, 3:29:18 am ISTRevision 1

In plain language

What this advisory means

A security vulnerability (CVE-2026-100308) was found in Amazon GluonTS, a library for deep learning models on time series data. It allows attackers to run any operating system commands if they load a manipulated model from an untrusted source. This can happen when users call deserialization functions on model directories they don't fully control.

Technical explanation

How the issue affects the environment

In Amazon GluonTS versions before 0.17.0, deserializing model artifacts with Predictor.deserialize() or RepresentablePredictor.deserialize() can lead to arbitrary command execution. This is due to unsafe deserialization of untrusted serialized model directories, enabling context-dependent attackers to execute OS commands with the privileges of the loading process.

Operational impact

Why teams should care

If exploited, attackers could execute arbitrary commands on systems running vulnerable GluonTS versions, potentially leading to full system compromise, data breaches, or disruption of business operations depending on the permissions held by the loading process.

Immediate action

Upgrade to GluonTS version 0.17.0 or later, or ensure forked or derivative code includes the fixes. Only deserialize model artifacts from trusted sources.

Affected and fixed releases

Affected versionsGluonTS versions before 0.17.0
Fixed versionsGluonTS version 0.17.0

Temporary risk reduction

Avoid deserializing model directories unless they come from fully trusted and verified sources.

Evidence and validation checklist

  • AWS Security Bulletin 2026-119-AWS dated 2026-09-29
  • CVE-2026-100308 entry confirmed by AWS
  • Acknowledgement of coordinated vulnerability disclosure by Michael Holmquist, Hasp Labs
  • Fix incorporated in GluonTS 0.17.0

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source