Executive brief
FedML is a machine learning library used for distributed training and federated learning. A vulnerability in its S3 storage backend allows remote attackers to execute arbitrary code by sending malicious serialized objects, potentially compromising systems using this library for model training or serving.
Technical details
An unsafe deserialization vulnerability exists in the S3Storage.read_model() function within the MQTT+S3 Communication Backend (fedml/core/distributed/communication/s3/remote_storage.py). The function improperly deserializes the s3_key_str argument without validation. An attacker with network access can exploit this to craft malicious serialized payloads that execute arbitrary code upon deserialization. No authentication is required, making remote exploitation straightforward. The vendor was notified early but has not responded; patch status is unknown.
Affected products
- FedML-AI FedML up to 0.9.6
Timeline
- 2026-09-14: disclosed