Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-10036
SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P H H H 8.7 .0046 37.8 —
AFFECTED
Product Versions Fixed
speechbrain unspecified —
TIMELINE
May 28 Reserved by VulnCheck
Aug 27 Published (CNA: VulnCheck)
Aug 28 EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.
Aug 29 EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.
Description
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file within the configured checkpoint path to trigger code execution during candidate discovery, even if the malicious checkpoint is never selected for recovery.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| May 28, 2026 | Reserved | Reserved by VulnCheck |
| August 27, 2026 | Published | Published (CNA: VulnCheck) |
| August 28, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added. |
| August 29, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| speechbrain | speechbrain | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-10036 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.