logo

Critical Flaw in Replicate AI Platform Exposes Proprietary Data

ID: 277353f0-a814-5c7d-ba39-1310ab1bc263

STIX ID: report--277353f0-a814-5c7d-ba39-1310ab1bc263

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-23

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Wiz researchers found a critical vulnerability in Replicate's AI-as-a-service platform where a malicious Cog-format container could achieve root-level remote code execution, move laterally within a Kubernetes cluster, and perform cross-tenant queries or modify other customers' models and outputs; the issue risked exposing proprietary model data and sensitive prompts, was responsibly disclosed to Replicate in January 2023, and has been mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.