CVE-2026-87083
Deferred Deferred - Pending Action

Deserialization Flaw in tile-ai tilelang

Vulnerability report for CVE-2026-87083, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulDB

Description

A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Applying a patch is advised to resolve this issue. Based on the release information, the fix has not been included in any official release yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tile-ai tilelang to 0.1.14 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unsafe deserialization flaw in the TileLang library's kernel cache system. It occurs because the software uses cloudpickle to serialize and deserialize kernel parameters and compiled function objects stored on disk. An attacker who can write files to the cache directory can place malicious pickle files, which are then executed when loaded by a victim, leading to arbitrary code execution.

Detection Guidance

Check for the presence of params.pkl or function.pkl files in the TileLang cache directory. These files indicate potential exploitation. Use commands like 'find / -name params.pkl 2>/dev/null' or 'find / -name function.pkl 2>/dev/null' to locate them. Also inspect cache directories for unexpected files or modifications.

Impact Analysis

If you use TileLang, an attacker with access to your cache directory could execute arbitrary code on your system. This could lead to data theft, system compromise, or further network attacks. The attack can be performed remotely if the attacker can control the cache directory or exploit another filesystem write vulnerability.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data confidentiality and integrity requirements in GDPR and HIPAA. If exploited, it may result in unauthorized access to sensitive data, leading to compliance breaches and legal consequences.

Mitigation Strategies

Apply the patch from commit 11ec2397fe942e8b422d026af4a03d6e0a55ae6c. Remove any existing params.pkl or function.pkl files in the cache directory. Ensure the cache directory is not writable by untrusted users. Monitor for unauthorized cache directory access or file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87083. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart