PT-2026-91024 · Fedml · Fedml
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FedML-AI FedML versions prior to 0.9.7
Description
An unsafe deserialization issue exists within the MQTT+S3 Communication Backend. The problem occurs in the
S3Storage.read model() function located in the fedml/core/distributed/communication/s3/remote storage.py file. By manipulating the s3 key str argument, a remote attacker can cause the system to deserialize untrusted data from an attacker-controlled S3 object, potentially leading to remote code execution. Deserialization is the process of converting a serialized format (like a byte stream) back into an object in memory.Recommendations
Restrict write access to model-storage buckets to ensure only trusted entities can upload artifacts.
Verify the integrity of model artifacts before loading them.
Isolate workers responsible for loading models.
Minimize runtime privileges for model-loading processes.
As a temporary mitigation, avoid using the
s3 key str argument in the S3Storage.read model() function with untrusted sources until a patch is available.Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fedml