Executive brief
A security vulnerability has been identified in the Feast Feature Server, a tool used to manage and serve data for machine learning models. An unauthorized person could remotely access and read sensitive files on the server, such as system configurations and login credentials. This could lead to a full compromise of the server and the data it handles.
Technical details
A path traversal vulnerability (CWE-22) exists in the Feast Feature Server's `/read-document` endpoint. The flaw allows an unauthenticated remote attacker to perform arbitrary file reads by submitting a specially crafted HTTP POST request. Successful exploitation enables the retrieval of any file accessible to the server process, including sensitive configuration files and credentials. The vulnerability affects Feast versions up to and including 0.58.0 and is also present in Red Hat OpenShift AI (RHOAI) components utilizing the feature server. Security engineers should verify if their deployments use the affected endpoint and apply updates from the vendor.
Affected products
- Feast Feast Feature Server <= 0.58.0
- Red Hat OpenShift AI (RHOAI) Affected
Timeline
- 2026-01-13: disclosed: Initial report in Red Hat Bugzilla
- 2026-03-20: advisory: NVD and Red Hat published advisory