Netskope Threat Labs

FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt

IPS-CFWIPS-SWG

1 SID: 66128

First seen
June 2026
Last seen
July 2026

Detects content exploiting CVE-2025-45146, unsafe deserialization in the CodeFuse ModelCache service that can allow code execution. The rule matches the pickled payloads that public exploits use to run code when the cache loads them.