Impact
Angel up to version 3.3.0 uses Kryo for deserialization of arbitrary classes without class registration or allowlist. An unauthenticated attacker who can reach the master RPC endpoint can send a crafted serialized payload that causes the JVM to instantiate arbitrary classes. This can lead to remote code execution under the permissions of the master node or result in denial of service through memory exhaustion.
Affected Systems
The vulnerability affects Angel-ML Angel platforms running version 3.3.0 or earlier. Systems exposed to untrusted networks that communicate with the master RPC endpoint are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 indicates high severity. An EPSS score of less than 1% shows that exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog. However, the attack vector is network‑based and unauthenticated; an attacker only needs connectivity to the master RPC port to deliver the malicious payload.
OpenCVE Enrichment