OmniGen2-RL Reward Server Unsafe Deserialization RCE
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execution on the host system running the exposed service.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Beijing Academy of Artificial Intelligence (BAAI) · OmniGen2-RLpublic PoCs found — 1
cve_referencechocapikk.com/posts/2026/omnigen2-pickle-rce/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://arxiv.org/abs/2506.18871https://chocapikk.com/posts/2026/omnigen2-pickle-rce/https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L208https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_proxy.py#L224https://github.com/VectorSpaceLab/OmniGen2/blob/3a13017e532f9f309a38bca571fd62200a6415c5/OmniGen2-RL/reward_server/reward_server.py#L118https://github.com/VectorSpaceLab/OmniGen2/pull/139https://www.vulncheck.com/advisories/omnigen2-rl-reward-server-unsafe-deserialization-rce