bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Tuesday, September 29, 2026

GluonTS Vulnerability Allows Arbitrary Command Execution

AWS GluonTS versions before 0.17.0 have a critical vulnerability (CVE-2026-100308) that lets attackers execute arbitrary commands when deserializing untrusted model files. If you're using GluonTS and loading models from untrusted sources via Predictor.deserialize() or RepresentablePredictor.deserialize(), you need to upgrade immediately. This is a serious one—attackers could run OS commands with your process privileges. Update to version 0.17.0 or later ASAP.

source: [aws/security-bulletin]