CVE-2026-15535

MEDIUM

AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization

Title source: cna
STIX 2.1

Description

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to deserialization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377885 | AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
https://vuldb.com/vuln/377885
Signature, Permissions Required signature permissions-required
VDB-377885 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377885/cti
Third Party Advisory third-party-advisory
CVE-2026-15535 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15535
Third Party Advisory third-party-advisory
Submit #854999 | AkariAsai self-rag 1fcdc420e48f50a7d7ab1ece5494221b93252e99 Unsafe Deserialization / Integrity Bypass
https://vuldb.com/submit/854999
Exploit exploit issue-tracking
https://github.com/AkariAsai/self-rag/issues/105

Scores

CVSS v3 6.3
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-502
Status published
Products (1)
AkariAsai/self-rag 1fcdc420e48f50a7d7ab1ece5494221b93252e99
Published Jul 13, 2026
Tracked Since Jul 13, 2026