logo

AI-as-a-Service Providers Vulnerable to PrivEsc and Cross-Tenant Attacks

ID: b1f9342a-a05f-59fc-8da6-94d1865a732b

STIX ID: report--b1f9342a-a05f-59fc-8da6-94d1865a732b

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-04-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

New research found critical vulnerabilities in AI-as-a-service platforms (illustrated against Hugging Face) where untrusted Pickle-based PyTorch models and malicious Dockerfiles can trigger remote code execution, container escape, takeover of CI/CD pipelines, and internal container registry compromise — enabling cross-tenant access to private models. Researchers recommend avoiding Pickle in production, sandboxing untrusted models, enabling IMDSv2 with Hop Limit, and using MFA; Hugging Face reported it has patched the identified issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.