Fedml · Fedml · CVE-2026-90614
**Name of the Vulnerable Software and Affected Versions**
FedML-AI FedML versions prior to 0.9.7
**Description**
An unsafe deserialization issue exists within the MQTT+S3 Communication Backend. The problem occurs in the `S3Storage.read model()` function located in the `fedml/core/distributed/communication/s3/remote storage.py` file. By manipulating the `s3 key str` argument, a remote attacker can cause the system to deserialize untrusted data from an attacker-controlled S3 object, potentially leading to remote code execution. Deserialization is the process of converting a serialized format (like a byte stream) back into an object in memory.
**Recommendations**
Restrict write access to model-storage buckets to ensure only trusted entities can upload artifacts.
Verify the integrity of model artifacts before loading them.
Isolate workers responsible for loading models.
Minimize runtime privileges for model-loading processes.
As a temporary mitigation, avoid using the `s3 key str` argument in the `S3Storage.read model()` function with untrusted sources until a patch is available.