Executive brief
SkyPilot, a tool for managing and scaling AI workloads across different cloud providers, contains a security flaw in how it handles user identification. The system uses a weak method for hashing usernames, which could potentially allow an attacker to manipulate user-related data. While the attack is complex to perform, it could impact the integrity of how users are identified within the system.
Technical details
A vulnerability classified as Use of a Broken or Risky Cryptographic Algorithm (CWE-327/CWE-328) exists in SkyPilot up to version 0.12.0. The flaw is located in the `username.encode` function within `sky/users/server.py`, which serves as the User ID Handler. The component utilizes a weak hashing algorithm for processing user identifiers. An attacker can attempt to exploit this remotely, though the attack is characterized by high complexity and difficult exploitability. While a public exploit is reported to exist, specific details on the replacement algorithm or patch version were not explicitly detailed in the advisory beyond the affected version range.
Affected products
- skypilot-org skypilot up to 0.12.0
Timeline
- 2026-03-26: disclosed: Initial contact with vendor via GitHub issue
- 2026-06-28: advisory: NVD publication date