Cleartext Storage Vulnerability in Amazon SageMaker Python SDK
CVE-2026-83551
8.5HIGH
What is CVE-2026-83551?
The Amazon SageMaker Python SDK prior to v3.11.0 and v2.256.0 has a vulnerability where sensitive information, including HMAC signing keys, is stored in cleartext within the @step and @remote decorator pipeline components. This exposure allows authenticated remote users to access the HMAC signing key from SageMaker DescribePipeline API responses. Consequently, they can forge valid integrity signatures for maliciously crafted function payloads, potentially executing unauthorized code in another user's pipeline execution context within the same AWS account.
Affected Version(s)
sagemaker-python-sdk 0 < 3.11.0
sagemaker-python-sdk 0 < 2.256.0
