Database/AI/ML frameworks & serving
TensorFlow / Keras: Arbitrary code execution via unsafe YAML deserialization of model config
CVSS 9.3CVE-2021-37678AI/ML frameworks & servingcurated
Impact
Arbitrary code execution via unsafe YAML deserialization of model config
Who can reach it
Customer-supplied model YAML
What to do
Historical but still present in pinned tenant envs; patch base images
References
Related entries
- MLflow (tracking server): Path traversal (`\..\filename`)CVE-2023-1177 · MLflow (tracking server)Critical
- Ray (dashboard /static/ file handler): Path traversal under the dashboard's /static/ route lets an unauthenticatedCVE-2023-6020 · Ray (dashboard /static/ file handler)Critical
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCVE-2024-3573 · MLflow (LFI via URI parsing)Critical
- Milvus: Unauthenticated attacker exploits the server directlyCVE-2025-64513 · MilvusCritical
- Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socketCVE-2026-101065 · Obot AI agent/MCP platform (documented Docker quickstart)Critical
- OpenShift AI guardrails-detectors: unauthenticated blind SSRF and file read via crafted XSDCVE-2026-15378 · Red Hat OpenShift AI guardrails-detectors (XSD schema parsing)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.