{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/feast/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-18948"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Feast"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Feast"],"content_html":"\u003cp\u003eCVE-2026-18948 is a critical vulnerability within the Feast feature store platform. The flaw stems from the insecure deserialization of user-defined functions (UDFs) stored within the system registry, which utilize the 'dill' Python serialization library. Because 'dill' is capable of serializing complex Python objects, including code, an attacker can craft and store a malicious UDF that executes arbitrary commands upon deserialization.\u003c/p\u003e\n\u003cp\u003eIn default configurations, remote unauthenticated attackers can inject these malicious payloads to gain code execution on the feature server. Furthermore, authenticated users can exploit the same deserialization process to bypass authorization checks, potentially leading to cross-tenant data access and facilitate lateral movement across the infrastructure. This vulnerability poses a severe risk to organizations leveraging Feast for machine learning pipelines.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution on the feature server. An attacker can gain control of the feature store, access sensitive model data, manipulate training features to poison machine learning models, or pivot deeper into the internal network to compromise additional cloud-native assets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Feast to a patched version that replaces or secures the 'dill' deserialization implementation.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation around Feast registry and feature server endpoints to prevent unauthorized access.\u003c/li\u003e\n\u003cli\u003eReview all existing UDFs stored in the registry for suspicious or unexpected code patterns.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the Feast API to identify unauthorized write operations to the registry endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:39:19Z","date_published":"2026-08-10T21:35:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18948-feast-deserialization/","summary":"Feast improperly deserializes user-defined functions via the 'dill' library, allowing remote unauthenticated attackers to achieve arbitrary code execution on feature servers.","title":"Critical Arbitrary Code Execution in Feast via UDF Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18948-feast-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Feast","version":"https://jsonfeed.org/version/1.1"}