Critical Flaw in Replicate AI Platform Exposes Proprietary Data
ID: 277353f0-a814-5c7d-ba39-1310ab1bc263
STIX ID: report--277353f0-a814-5c7d-ba39-1310ab1bc263
Feed Name: Dark Reading
Date Published: 2024-05-23
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Wiz researchers found a critical vulnerability in Replicate's AI-as-a-service platform where a malicious Cog-format container could achieve root-level remote code execution, move laterally within a Kubernetes cluster, and perform cross-tenant queries or modify other customers' models and outputs; the issue risked exposing proprietary model data and sensitive prompts, was responsibly disclosed to Replicate in January 2023, and has been mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
