๐Ÿ” CVE Alert

CVE-2026-86288

MEDIUM 6.3

ModelCloud GPTQModel Triton dequantization kernel tritonv2.py out-of-bounds

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.3.0 is able to resolve this issue. The name of the patch is 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. Upgrading the affected component is recommended.

CWE CWE-125 CWE-119
Vendor modelcloud
Product gptqmodel
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for modelcloud gptqmodel

Be the first to know when new medium vulnerabilities affecting modelcloud gptqmodel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ModelCloud / GPTQModel
7.0 7.1 7.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/399447 vuldb.com: https://vuldb.com/vuln/399447/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86288 vuldb.com: https://vuldb.com/submit/906135 github.com: https://github.com/ModelCloud/GPTQModel/issues/2949 github.com: https://github.com/ModelCloud/GPTQModel/pull/2950 github.com: https://github.com/ModelCloud/GPTQModel/commit/877c732f7d7dccd56a729844c6a5bd20f3aa8bb1 github.com: https://github.com/ModelCloud/GPTQModel/releases/tag/v7.3.0 github.com: https://github.com/ModelCloud/GPTQModel/

Credits

๐Ÿ” m00dy (VulDB User)