CVE-2026-25873
OmniGen2-RL Reward Server Unsafe Deserialization RCE
Vexday Risk Score
48Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 9.3EPSS 1.1%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Ciclo de vida
18 mar 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execution on the host system running the exposed service.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Beijing Academy of Artificial Intelligence (BAAI) · OmniGen2-RLPoCs públicas encontradas — 1
cve_referencechocapikk.com/posts/2026/omnigen2-pickle-rce/no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://arxiv.org/abs/2506.18871https://chocapikk.com/posts/2026/omnigen2-pickle-rce/https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L208https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L224https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_server.py#L118https://github.com/VectorSpaceLab/OmniGen2/pull/139https://www.vulncheck.com/advisories/omnigen2-rl-reward-server-unsafe-deserialization-rce