Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90614

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 16%
0.00247
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.3
github
7 дней назад

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 16%
0.00247
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20
Уязвимость CVE-2026-90614