{
  "title": "CVE of the day — CVE-2026-90777 (CVSS 8,8, high)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE of the day — CVE-2026-90777 (CVSS 8,8, high)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-90777: High vulnerability, CVSS 8,8/10, unsafe deserialization type, exploitable"
    }
  ],
  "description": "CVE-2026-90777: High vulnerability, CVSS 8,8/10, unsafe deserialization type, exploitable remotely, without privileges, with user interaction. ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from..",
  "keywords": [
    "c",
    "cve-2026-90777",
    "vulnerability",
    "high vulnerability",
    "♪",
    "cvs",
    "cybersecurity",
    "cybersecurity",
    "♪",
    "security update"
  ],
  "scenes": [
    {
      "title": "CVE-2026- 907",
      "subtitle": "CVSS 8.8",
      "text": "CVE-2026-90777: High gravity, CVSS score 8.8 out of 10 according to the National Vulnerability Database."
    },
    {
      "title": "Non-safe deserialization",
      "subtitle": "unsafe deserialization · CVSS v3.1",
      "text": "ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files.."
    },
    {
      "title": "EXPOSURE AND MITIGATION",
      "subtitle": "remotely exploitable, without privileges, with user interaction",
      "text": "Vulnerability exploitable remotely, without privileges, with user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ],
  "publication_date": "2026-09-15T01:04:58.819Z",
  "duration": 20,
  "topic": "cve",
  "lang": "en",
  "translation_group": "cve-2026-09-15",
  "poster": "cve-2026-09-15-en.jpg",
  "preview": "cve-2026-09-15-en.gif",
  "og_card": "cve-2026-09-15-en.og.jpg",
  "audiogram": "cve-2026-09-15-en.audiogram.mp4",
  "captions": "cve-2026-09-15-en.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-90777: High gravity, CVSS score 8.8 out of 10 according to the National Vulnerability Database. ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files.. Vulnerability exploitable remotely, without privileges, with user interaction. Apply the update of the supplier promptly and consult the official notice on NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-90777: High gravity, CVSS score 8.8 out of 10 according to the National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files.."
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Vulnerability exploitable remotely, without privileges, with user interaction. Apply the update of the supplier promptly and consult the official notice on NVD."
    }
  ]
}