THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-96p9-rh4f-92cf (high) — Windows ML CLI: CORS misconfig enables localhost RCE

[GHSA] GHSA-96p9-rh4f-92cf (high) — Windows ML CLI: CORS misconfig enables localhost RCE

highgithub_advisoriesPublished 2026-09-08

GHSA-96p9-rh4f-92cf Severity: high CVE: CVE-2026-84452

Windows ML CLI: CORS misconfig enables localhost RCE

Case Description:

MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the 'serve/cli_api.py' component of the 'winml-cli' project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets '

Indicators of compromise

Original source: https://github.com/advisories/GHSA-96p9-rh4f-92cf