Impact
A weakness exists in FedML‑AI’s MQTT+S3 communication backend where manipulating the s3_key_str argument causes the S3Storage.read_model function to deserialize untrusted data, enabling remote exploitation. The flaw involves improper input validation (CWE‑20) and unsafe deserialization of external data (CWE‑502), which could allow an attacker to execute arbitrary code or otherwise compromise system integrity.
Affected Systems
FedML earlier are affected. The issue resides in the MQTT+S3 communication backend within fedml/core/distributed/communication/s3/remote_storage.py. Deployments using these versions without containment measures are at risk.
Risk and Exploitability
With a CVSS base score of 5.3 the vulnerability is considered moderate. The EPSS score is <1%, indicating a very low exploit probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, requiring an attacker to send a crafted s3_key_str value to the MQTT+S3 endpoint. Although publicly available exploit code is not reported, the deserialization nature suggests that environments exposing the endpoint to untrusted traffic could be vulnerable.
OpenCVE Enrichment