{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/zenml/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZenML (0.94.6)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","deserialization","zenml"],"_cs_type":"advisory","_cs_vendors":["ZenML"],"content_html":"\u003cp\u003eZenML version 0.94.6 contains a remote code execution vulnerability (CVE-2026-68772) within the CloudpickleMaterializer component. This vulnerability stems from the use of unsanitized \u003ccode\u003ecloudpickle.load()\u003c/code\u003e calls when materializing artifacts from the artifact store. An attacker who gains write access to the shared artifact store can replace a legitimate \u003ccode\u003eartifact.pkl\u003c/code\u003e file with a crafted payload containing a malicious \u003ccode\u003e__reduce__\u003c/code\u003e method. When a legitimate pipeline or user subsequently materializes this artifact, the Python environment automatically executes the embedded malicious commands. This vulnerability is critical for organizations using shared artifact storage in multi-user environments where local write access or compromised service accounts could allow for persistence or lateral movement within the data pipeline ecosystem.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains write access to a shared artifact storage location used by ZenML.\u003c/li\u003e\n\u003cli\u003eAttacker locates a target \u003ccode\u003eartifact.pkl\u003c/code\u003e file used by an active or future pipeline.\u003c/li\u003e\n\u003cli\u003eAttacker generates a malicious pickle payload using \u003ccode\u003ecloudpickle\u003c/code\u003e that defines a \u003ccode\u003e__reduce__\u003c/code\u003e method to execute system commands.\u003c/li\u003e\n\u003cli\u003eAttacker overwrites the legitimate \u003ccode\u003eartifact.pkl\u003c/code\u003e file with the malicious payload.\u003c/li\u003e\n\u003cli\u003eA victim user or automated pipeline execution agent triggers the \u003ccode\u003eCloudpickleMaterializer\u003c/code\u003e to process the artifact.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eCloudpickleMaterializer\u003c/code\u003e executes \u003ccode\u003ecloudpickle.load()\u003c/code\u003e on the malicious file.\u003c/li\u003e\n\u003cli\u003eThe embedded commands in the \u003ccode\u003e__reduce__\u003c/code\u003e method are executed in the security context of the pipeline process.\u003c/li\u003e\n\u003cli\u003eAttacker gains arbitrary code execution, potentially resulting in exfiltration or further compromise of the compute environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution within the context of the pipeline process. This can lead to full system compromise, data exfiltration from the artifact store, or unauthorized access to credentials and sensitive data processed by the data pipelines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade ZenML to a patched version immediately to resolve the unsafe deserialization vulnerability in the CloudpickleMaterializer.\u003c/li\u003e\n\u003cli\u003eRestrict write access to shared artifact storage locations to only authorized service accounts or users.\u003c/li\u003e\n\u003cli\u003eMonitor file integrity for \u003ccode\u003eartifact.pkl\u003c/code\u003e files within the ZenML artifact store for unauthorized modifications.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) on cloud-based artifact storage (e.g., S3, GCS) to ensure only authorized CI/CD pipelines can modify stored objects.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-07T17:34:43Z","date_published":"2026-08-07T17:34:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zenml-rce/","summary":"ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows arbitrary command execution via malicious pickle file injection.","title":"Remote Code Execution in ZenML CloudpickleMaterializer","url":"https://feed.craftedsignal.io/briefs/2026-08-zenml-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Zenml","version":"https://jsonfeed.org/version/1.1"}