Database/AI/ML frameworks & serving

Kubeflow Community Distribution: Insecure default in the platform install
Impact
Insecure default in the platform install
Who can reach it
Tenant user of a Kubeflow-based platform
What to do
Upgrade to 26.03-rc.1+; provider-owned if the provider ships managed Kubeflow
Fleet impact
How widespread
Common - Kubeflow is a standard multi-tenant ML platform layer over GPU K8s; official manifests before 1.10 and most packaged distros affected
Cost to remediate
daemon-restart - Istio policy and manifest upgrade; the expensive part is invalidating every user token issued before the fix
Why it hits the whole fleet
Overly permissive Istio permissions let any user with kubeflow-edit in *any* namespace create a notebook that steals other users' authorization tokens - a straight cross-tenant takeover on a shared AI platform
References
Related entries
- PyTorch (mobile interpreter): Use-after-free in `torch/csrc/jit/mobile/interpreter.cpp`CVE-2024-31583 · PyTorch (mobile interpreter)High
- langchain-experimental (Python REPL): Python REPL exposed without an opt-inCVE-2024-38459 · langchain-experimental (Python REPL)High
- LangChain (`FAISS.deserialize_from_bytes`): Pickle deserialization of an untrusted vector indexCVE-2024-5998 · LangChain (`FAISS.deserialize_from_bytes`)High
- picklescan: Improper input validation lets a crafted pickle evade scanningCVE-2025-10155 · picklescanHigh
- LlamaIndex CLI: OS command injection via the `--files` argumentCVE-2025-1753 · LlamaIndex CLIHigh
- nbconvert: Template-driven conversion executes attacker contentCVE-2025-53000 · nbconvertHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.