Home ยป Database

AVID-2026-R0812

Description

Vulnerability CVE-2021-31681

Details

Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.

Reason for inclusion in AVID: CVE-2021-31681 describes a deserialization-based remote code execution vulnerability in YOLOv3 via crafted YAML input. This directly impacts AI software stacks (models/config parsing, inference pipelines) and affects components used to build/deploy AI systems. It is a software vulnerability with clear security impact, and the affected artifact is part of AI tooling, thus relevant to the AI general-purpose systems supply chain.

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
Systemn/a

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-07-31
  • Version: 0.3.3
  • AVID Entry