ktransformers npm Package Vulnerability: Early Warning Issued
An early warning has been issued regarding a critical vulnerability in the ktransformers npm package, versions up to and including 0.6.3. This vulnerability, tracked as CVE-2026-63767, allows unauthenticated remote attackers to execute arbitrary commands.
What happened
The ktransformers npm package, up to and including version 0.6.3, is under investigation for containing an unauthenticated pickle deserialization vulnerability. This vulnerability, identified as CVE-2026-63767, reportedly allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. The issue is fixed in commit def0f93.
To assess your exposure, check if your project dependencies include ktransformers version 0.6.3 or earlier. If so, it is recommended to upgrade to version def0f93 or higher to mitigate the risk. The CVSS score for this vulnerability is 9.8, indicating a critical severity level.
For more detailed information, consult the primary sources, including the NVD page for CVE-2026-63767. The vulnerability metrics and further technical details can be found there. Stay tuned for updates as the situation develops.
How 0Day mitigates this
ktransformers is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.