Remote Code Execution With Modern AI/ML Formats and Libraries
ID: deb46c7c-e4c6-5d39-b68f-410b70b45074
STIX ID: report--deb46c7c-e4c6-5d39-b68f-410b70b45074
Feed Name: Palo Alto Networks Unit 42
This Unit 42 report details RCE vulnerabilities in three AI/ML Python libraries (NeMo, uni2TS, ml-flextok) that occur when malicious metadata in model files is passed to Hydra's instantiate() function, enabling arbitrary code execution when models are loaded (including models hosted on HuggingFace). The report provides technical analysis, affected models and formats, vendor disclosures and CVEs, and notes that fixes and mitigations were issued and no active exploitation was observed as of publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
