Executive brief
The Adversarial Robustness Toolbox (ART), a library used by developers and researchers to evaluate the security of machine learning models, contains a critical flaw in its Kubeflow component. An attacker can exploit this vulnerability to execute malicious code on the system running the evaluation. This could lead to a complete takeover of the server, potentially exposing sensitive AI models, training data, or corporate infrastructure.
Technical details
A code injection vulnerability (CWE-94) exists in the Adversarial Robustness Toolbox (ART) through version 1.20.1. The robustness evaluation function for PyTorch models within the Kubeflow component utilizes the unsafe Python eval() function to process user-supplied strings for 'LossFn' and 'Optimizer' parameters. Because these strings are not sanitized or restricted, a remote attacker can provide a specially crafted payload containing arbitrary Python code. Successful exploitation results in the execution of that code with the privileges of the ART process, leading to full system compromise. Red Hat has also identified this vulnerability as affecting Red Hat OpenShift AI (RHOAI).
Affected products
- Trusted-AI Adversarial Robustness Toolbox (ART) thru 1.20.1
- Red Hat Red Hat OpenShift AI (RHOAI)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
References
- https://github.com/Trusted-AI/adversarial-robustness-toolbox
- https://www.notion.so/CVE-2026-31228-35d1e1393188817f9ab0dc4b1651dfe9
- https://access.redhat.com/security/cve/CVE-2026-31228
- https://bugzilla.redhat.com/show_bug.cgi?id=2476522
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31228.json