CVE-2026-7584Disclosure(zhinst / labone_q)

LOWCVSS 8.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names from the serialized data without any validation of the target class or restriction on which modules could be imported. An attacker can craft a serialized experiment file that causes the deserialization engine to import and instantiate arbitrary Python classes with attacker-controlled constructor arguments, resulting in arbitrary code execution in the context of the user running the Python process. Exploitation requires the victim to load a malicious file using LabOne Q's deserialization functions, for example a compromised experiment file shared for collaboration or support purposes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • labone_q

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
labone_q

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-01: 3Technical Details · 2026-05-01: 205-01
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🛡️ CVE-2026-7584: LabOne Q serialization framework suffers from unsafe deserialization in import_cls, allowing unauthenticated attackers to achieve arbitrary code execution via crafted serialized files. #LabOneQ #RCE #Deserialization #Security https://nvd.nist.gov/vuln/detail/CVE-2026-7584

    Post summary

    LabOne Q framework has an unsafe deserialization flaw (CVE‑2026‑7584) that allows unauthenticated attackers to achieve arbitrary code execution, but no PoC, exploit tool, active exploitation, or patch is mentioned.

    1004059
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7584 The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to t… https://www.cve.org/CVERecord?id=CVE-2026-7584

    Post summary

    The tweet announces CVE‑2026‑7584, noting a class‑loading mechanism in the LabOne Q serialization framework, but offers no PoC, exploitation details, or fixes.

    00010127
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7584 Arbitrary Code Execution via Unsafe Deserialization in LabOne Q Serialization Framework https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7584

    Post summary

    The text merely announces CVE-2026-7584, stating it allows arbitrary code execution through unsafe deserialization in LabOne Q's serialization framework, with no further exploitation details or remediation referenced.

    0000030
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appzhinstlabone_q---
Appzhinstlabone_q26.4.0--
Appzhinstlabone_q26.4.0--
Appzhinstlabone_q26.4.0--
Appzhinstlabone_q26.4.0--
Appzhinstlabone_q26.4.0--

Explore more