PT-2026-91024 · Fedml · Fedml

·

CVE-2026-90614

·

Published

2026-09-14

·

Updated

2026-09-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FedML-AI FedML versions prior to 0.9.7
Description An unsafe deserialization issue exists within the MQTT+S3 Communication Backend. The problem occurs in the S3Storage.read model() function located in the fedml/core/distributed/communication/s3/remote storage.py file. By manipulating the s3 key str argument, a remote attacker can cause the system to deserialize untrusted data from an attacker-controlled S3 object, potentially leading to remote code execution. Deserialization is the process of converting a serialized format (like a byte stream) back into an object in memory.
Recommendations Restrict write access to model-storage buckets to ensure only trusted entities can upload artifacts. Verify the integrity of model artifacts before loading them. Isolate workers responsible for loading models. Minimize runtime privileges for model-loading processes. As a temporary mitigation, avoid using the s3 key str argument in the S3Storage.read model() function with untrusted sources until a patch is available.

Fix

Deserialization of Untrusted Data

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90614

Affected Products

Fedml