rasa
Open source machine learning framework to automate text- and voice-based conversations: NLU, dialogue management, connect to Slack, Facebook, and more - Create chatbots and voice assistants
Activity
- Latest release
- 1y ago
- Total releases
- 360
- Cadence
- ~4 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- Apache-2.0
- First release
- Apr 28, 2015
| Version | Released | |
|---|---|---|
3.6.21
patch
| ||
3.6.20
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
3.6.19
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
3.6.18
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
3.6.17
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
3.6.16
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.16
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.5.17
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.17
patch
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
3.6.15
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.15
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.14
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.14
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.13
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.13
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.12
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.12
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.11
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.11
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.10
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.10
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.4.18
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.18
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.6.9
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.9
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.4.17
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.17
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.5.16
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.16
patch
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
3.6.8
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.8
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.7
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.7
patch
Dependencies (87)
+ 79 more
Changelog
Compare changes
|
|
3.6.6
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.6
patch
Dependencies (85)
+ 77 more
Changelog
Compare changes
|
|
3.6.5
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.5
patch
Dependencies (84)
+ 76 more
Changelog
Compare changes
|
|
3.6.4
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.4
patch
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.5.15
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.15
patch
Dependencies (81)
+ 73 more
Changelog
Compare changes
|
|
3.6.3
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.3
patch
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.7.0b2
pre
|
3.7.0b2
pre
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.5.14
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.14
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.4.16
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.16
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.3.12
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.3.12
patch
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.7.0b1
pre
|
3.7.0b1
pre
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.6.2
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.2
patch
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.5.13
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.13
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.4.15
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.15
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.6.1
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.1
patch
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.6.1a1
pre
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.1a1
pre
Dependencies (83)
+ 75 more
Changelog
Compare changes
|
|
3.5.12
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.12
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.6.0
minor
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.0
minor
Dependencies (84)
+ 76 more
Changelog
Compare changes
|
|
3.4.14
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.14
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.5.11
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.11
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.5.10
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.10
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.3.11
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.3.11
patch
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.4.13
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.13
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.5.9
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.9
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.6.0a1
pre
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.6.0a1
pre
Dependencies (82)
+ 74 more
Changelog
Compare changes
|
|
3.5.8
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.8
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.4.12
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.12
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.4.11
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.4.11
patch
Dependencies (77)
+ 69 more
Changelog
Compare changes
|
|
3.5.7
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.7
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.3.10
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.3.10
patch
Dependencies (76)
+ 68 more
Changelog
Compare changes
|
|
3.5.6
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.5.6
patch
Dependencies (80)
+ 72 more
Changelog
Compare changes
|
|
3.3.9
patch
1 CVE
CVE-2024-49375
PYSEC-2026-513
GHSA-cpv4-ggrr-7j9v
PYSEC-2026-514
Jun 29, 2026
Rasa Allows Remote Code Execution via Remote Model Loading
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
VulnerabilityA vulnerability has been identified in Rasa Pro and Rasa Open Source that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are:
FixWe encourage you to upgrade to a version of Rasa that includes a fix. These are:
Once you have upgraded your Rasa Pro or Open Source installation, you will need to retrain your model using the fixed version of Rasa Pro or Open Source. If you have a custom component that inherits from one of the components listed below and modified the persist or load method, make sure to update your code. Please contact us in case you encounter any problems. Affected components:
If you are unable to upgrade immediately, please follow our mitigation advice below. Mitigation Advice
Future ReleasesAs an additional security step, a future release of Rasa Pro will remove the ability to enable the API without any authentication method enabled. CreditRasa would like to thank Julian Scheid from Deutsche Telekom Security GmbH for responsible disclosure of this vulnerability. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.14.0a5
0.14.0a6
0.14.0a7
0.14.0a8
0.14.0a9
+ 345 more Show less
0.15.0a6
0.2.0a2
0.2.0a3
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0rc1
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc5
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.10.0
1.10.0a1
1.10.0a2
1.10.1
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0
1.2.0a2
1.2.0a3
1.2.0a4
1.2.0a5
1.2.0a6
1.2.0a7
1.2.1
1.2.10
1.2.11
1.2.12
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.0a1
1.3.0a2
1.3.1
1.3.10
1.3.1a1
1.3.1a10
1.3.1a11
1.3.1a12
1.3.1a14
1.3.1a3
1.3.1a4
1.3.1a5
1.3.1a8
1.3.2
1.3.3
1.3.4
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.0a1
1.6.0a2
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
2.0.0
2.0.0a1
2.0.0a2
2.0.0a3
2.0.0a4
2.0.0a5
2.0.0a6
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.0a1
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.4.0
2.4.1
2.4.2
2.4.3
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.10
2.8.11
2.8.12
2.8.13
2.8.14
2.8.15
2.8.16
2.8.17
2.8.18
2.8.19
2.8.2
2.8.20
2.8.21
2.8.22
2.8.23
2.8.24
2.8.25
2.8.26
2.8.27
2.8.28
2.8.29
2.8.3
2.8.30
2.8.31
2.8.32
2.8.33
2.8.34
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
3.0.0
3.0.0rc1
3.0.0rc2
3.0.0rc3
3.0.1
3.0.11
3.0.12
3.0.13
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.13
3.2.2
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.3.0
3.3.0a1
3.3.1
3.3.10
3.3.11
3.3.12
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.4.0
3.4.1
3.4.10
3.4.11
3.4.12
3.4.13
3.4.14
3.4.15
3.4.16
3.4.17
3.4.18
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.5.0
3.5.0a1.dev1
3.5.0a2.dev1
3.5.0a2.dev2
3.5.0b1
3.5.1
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.16
3.5.17
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.5.9
3.6.0
3.6.0a1
3.6.1
3.6.10
3.6.11
3.6.12
3.6.13
3.6.14
3.6.15
3.6.16
3.6.17
3.6.18
3.6.19
3.6.1a1
3.6.2
3.6.20
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
Fixed in
3.6.21
References
Updated Jul 01, 2026 · Source: OSV.dev |
3.3.9
patch
Dependencies (76)
+ 68 more
Changelog
Compare changes
|