
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22584 is a code injection vulnerability (CWE-94) in Salesforce Uni2TS, a Python library for time-series modeling, affecting all versions through 1.2.0 across macOS, Windows, and Linux. The vulnerability allows attackers to leverage executable code in non-executable files, enabling remote code execution without authentication. It was published on January 9, 2026, with a patch available in version 2.0.0. It carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, Salesforce Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), mapped to CAPEC-35 (Leverage Executable Code in Non-Executable Files) and CAPEC-242 (Code Injection). The attack vector is network-based, requiring no privileges, no user interaction, and low attack complexity, meaning an unauthenticated remote attacker can trigger code execution by supplying malicious input that is interpreted as executable code within non-executable file contexts (e.g., model metadata or configuration files). This attack pattern is consistent with poisoned metadata attacks targeting AI/ML Python libraries used in Hugging Face model ecosystems (Unit 42, Red Hat CVE).
Successful exploitation results in complete system compromise across all three security dimensions: confidentiality (HIGH), integrity (HIGH), and availability (HIGH). A remote, unauthenticated attacker can execute arbitrary code on any system running Uni2TS ≤ 1.2.0, potentially enabling data exfiltration, persistent access, lateral movement within AI/ML infrastructure, and disruption of model serving pipelines. Given Uni2TS's use in AI/ML workflows often integrated with Hugging Face and similar platforms, exploitation could also affect downstream model consumers or shared compute environments (Unit 42, BankInfoSecurity).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.029% (0.000290), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score of 9.8, zero-authentication requirement, and the growing attack surface of AI/ML Python libraries make it a high-priority patching target (Unit 42).
bash, sh, cmd.exe, curl, wget, python) during Uni2TS model loading or inference operations.Salesforce has released a patch in Uni2TS version 2.0.0, which resolves this vulnerability. All users running Uni2TS ≤ 1.2.0 on any platform (Windows, macOS, Linux) should upgrade immediately using pip install --upgrade uni2ts. As a temporary workaround, restrict access to systems running Uni2TS, avoid loading model files or metadata from untrusted sources, and isolate AI/ML workloads in sandboxed environments. Contact Salesforce support for additional patch deployment guidance (Salesforce Advisory).
Unit 42 (Palo Alto Networks) published a threat intelligence report covering RCE vulnerabilities in AI Python libraries, including CVE-2026-22584, highlighting the risk of poisoned metadata attacks in the AI/ML supply chain (Unit 42). Multiple security news outlets including BankInfoSecurity, DataBreachToday, GovInfoSecurity, and HealthcareInfoSecurity covered the broader issue of flaws in AI libraries exposing models to remote code execution (BankInfoSecurity). The Hacker News included the vulnerability in its ThreatsDay bulletin, and community discussion appeared on Bluesky and Mastodon/InfoSec.Exchange, reflecting moderate security community awareness (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."