flair
A very simple framework for state-of-the-art NLP
Activity
- Latest release
- 1y ago
- Total releases
- 34
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jul 19, 2018
| Version | Released | |
|---|---|---|
0.15.1
patch
| ||
0.15.0
minor
| ||
0.14.0
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.2
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.11.3
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.11.2
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.11.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.11
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.10
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.9
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.8.0.post1
pre
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.8
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.7
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.1.post1
pre
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6.0.post1
pre
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.6
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.5
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.5
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.2.1
minor
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.1.1
initial
1 CVE
CVE-2024-10073
PYSEC-2026-1376
GHSA-9rw2-jf8x-cgwm
Jul 07, 2026
Flair allows arbitrary code execution
Medium
Network
High
None
None
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
0.1.1
0.10
0.11
0.11.1
0.11.2
0.11.3
0.12
0.12.1
0.12.2
0.13.0
0.13.1
0.14.0
+ 20 more Show less
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5
0.5.1
0.6
0.6.0.post1
0.6.1
0.6.1.post1
0.7
0.8
0.8.0.post1
0.9
Fixed in
0.15.0
References
Updated Jul 07, 2026 · Source: OSV.dev |