Junglewise Threat Intelligence

CVE-2026-5536: FedML-AI FedML insecure deserialization in gRPC server

CVE-2026-5536 · Severity: high · CVSS 7.3 · Published 2026-04-05

Technologies: Tensoropera Fedml. Vendors: Tensoropera.

Executive brief

FedML, a platform for federated machine learning, contains a security vulnerability in its communication server. An attacker can remotely send a specially crafted message to the server that forces it to execute malicious code. This could allow an unauthorized user to take full control of the machine learning node, potentially leading to data theft or disruption of the training process.

Technical details

FedML is vulnerable to Remote Code Execution (RCE) via the gRPC server component. The vulnerability exists in the sendMessage function within grpc_server.py, where incoming network messages are passed to pickle.loads() in grpc_comm_manager.py without prior validation. Because the gRPC server is configured to listen on all interfaces (0.0.0.0) using add_insecure_port() and does not require authentication, a remote attacker can send a malicious Python pickle payload to achieve arbitrary code execution. The vendor was notified but has not yet provided a patch; users should restrict network access to the gRPC ports (default 8890+).

Affected products

  • FedML-AI FedML up to 0.8.9

Timeline

  • 2026-03-18: disclosed: Initial disclosure on GitHub issues
  • 2026-04-05: advisory: NVD/VulDB advisory published

References

Related threats