THREAT OPS › Threat News › [GHSA] GHSA-96p9-rh4f-92cf (high) — Windows ML CLI: CORS misconfig enables localhost RCE
[GHSA] GHSA-96p9-rh4f-92cf (high) — Windows ML CLI: CORS misconfig enables localhost RCE
GHSA-96p9-rh4f-92cf Severity: high CVE: CVE-2026-84452
Windows ML CLI: CORS misconfig enables localhost RCE
Case Description:
MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the 'serve/cli_api.py' component of the 'winml-cli' project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets '
Indicators of compromise
- CVE-2026-84452cve
- http://127.0.0.1:8000/openapi.jsonurl
- http://127.0.0.1:8000/v1/cli/buildurl
- https://evil.exampleurl
Original source: https://github.com/advisories/GHSA-96p9-rh4f-92cf