VYPR
Medium severity6.3NVD Advisory· Published Sep 14, 2026

CVE-2026-90614

CVE-2026-90614

Description

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Tensoropera/Fedmlreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.9.6

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.