GHSA-96qh-x5p5-9v7xMediumCVSS 6.3
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the...
🔗 CVE IDs covered (1)
📋 Description
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90614
- https://github.com/FedML-AI/FedML/issues/2267
- https://github.com/FedML-AI/FedML
- https://vuldb.com/cve/CVE-2026-90614
- https://vuldb.com/submit/914219
- https://vuldb.com/vuln/403196
- https://vuldb.com/vuln/403196/cti
- https://github.com/advisories/GHSA-96qh-x5p5-9v7x