Junglewise Threat Intelligence

CVE-2026-13482: skypilot-org skypilot weak hash in User ID Handler

CVE-2026-13482 · Severity: low · CVSS 3.7 · Published 2026-06-28

Executive brief

SkyPilot, a tool for managing and scaling AI workloads across different cloud providers, contains a security flaw in how it handles user identification. The system uses a weak method for hashing usernames, which could potentially allow an attacker to manipulate user-related data. While the attack is complex to perform, it could impact the integrity of how users are identified within the system.

Technical details

A vulnerability classified as Use of a Broken or Risky Cryptographic Algorithm (CWE-327/CWE-328) exists in SkyPilot up to version 0.12.0. The flaw is located in the `username.encode` function within `sky/users/server.py`, which serves as the User ID Handler. The component utilizes a weak hashing algorithm for processing user identifiers. An attacker can attempt to exploit this remotely, though the attack is characterized by high complexity and difficult exploitability. While a public exploit is reported to exist, specific details on the replacement algorithm or patch version were not explicitly detailed in the advisory beyond the affected version range.

Affected products

  • skypilot-org skypilot up to 0.12.0

Timeline

  • 2026-03-26: disclosed: Initial contact with vendor via GitHub issue
  • 2026-06-28: advisory: NVD publication date

References