Database/AI/ML frameworks & serving

Kubeflow (Pipelines UI): Stored XSS in the pipeline view
CVSS 5.4CVE-2024-9526AI/ML frameworks & servingcurated
Impact
Stored XSS in the pipeline view
Who can reach it
Tenant-supplied pipeline definition rendered to another user
What to do
Upgrade; multi-tenant Kubeflow UIs share an origin
References
Related entries
- JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRFCVE-2026-102904 · JupyterLab PyPI Extension Manager (uninstall handler argument injection)Medium
- Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalationCVE-2026-24693 · Intel oneCCL Bindings for PyTorch (protection mechanism failure)Medium
- TorchServe (model/workflow API): Information disclosure of files on the serving hostCVE-2023-48299 · TorchServe (model/workflow API)Medium
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`CVE-2025-5197 · HuggingFace transformersMedium
- mcp-kubernetes-server: chained kubectl commands bypass the read-only --disable-write/--disable-delete guardsCVE-2025-59376 · feiskyer mcp-kubernetes-server (--disable-write / --disable-delete command guards)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.