GPU VulnDB

Database/Control plane, storage & DevOps

SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of the

CVE-2026-13482Control plane, storage & DevOpscurated

Impact

User IDs are derived with a weak hash of the username, so a remote attacker can work toward a collision and get a user ID that belongs to someone else. Practical exploitation is difficult, but the failure mode is identity confusion in the layer that decides whose clusters and quota a request touches.

Who can reach it

Remote, unauthenticated, but high attack complexity. Affects SkyPilot up to 0.12.0. The exploit has been published.

What to do

Upgrade SkyPilot past 0.12.0 once the maintainers ship the fix tracked in issue 9194, and restart the API server. This is a VulDB-sourced report - confirm against the SkyPilot release notes before scheduling a maintenance window on it alone.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.