NPM · JULY 2026 · EARLY WARNING

ktransformers npm Package Vulnerability: Early Warning Issued

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-63767Severity: CRITICAL

An early warning has been issued regarding a critical vulnerability in the ktransformers npm package, versions up to and including 0.6.3. This vulnerability, tracked as CVE-2026-63767, allows unauthenticated remote attackers to execute arbitrary commands.

What happened

The ktransformers npm package, up to and including version 0.6.3, is under investigation for containing an unauthenticated pickle deserialization vulnerability. This vulnerability, identified as CVE-2026-63767, reportedly allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. The issue is fixed in commit def0f93.

To assess your exposure, check if your project dependencies include ktransformers version 0.6.3 or earlier. If so, it is recommended to upgrade to version def0f93 or higher to mitigate the risk. The CVSS score for this vulnerability is 9.8, indicating a critical severity level.

For more detailed information, consult the primary sources, including the NVD page for CVE-2026-63767. The vulnerability metrics and further technical details can be found there. Stay tuned for updates as the situation develops.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ktransformers is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats