The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate
ID: a31c45f9-9066-5d0b-a596-467c1b30b2c9
STIX ID: report--a31c45f9-9066-5d0b-a596-467c1b30b2c9
Feed Name: Wiz Blog
Threat Score
Wiz Research found a critical tenant-isolation vulnerability on the Replicate platform where a maliciously crafted Cog container enabled root remote code execution and, by injecting packets into a shared network namespace TCP stream to a Redis queue, could intercept and alter other customers' prediction prompts and outputs; the issue was responsibly disclosed and quickly mitigated with no reported customer data compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
