Deserialization Vulnerability in FedML-AI's MQTT+S3 Communication Backend
CVE-2026-90614
5.3MEDIUM
What is CVE-2026-90614?
A deserialization vulnerability has been identified in the MQTT+S3 Communication Backend of FedML-AI. Specifically, the issue arises in the S3Storage.read_model function located in remote_storage.py. Manipulation of the s3_key_str argument enables remote attackers to exploit this vulnerability, potentially leading to unauthorized access and actions within the affected systems. Despite being reported to the project, there has been no response or remediation action from the developers.
Affected Version(s)
FedML 0.9.0
FedML 0.9.1
FedML 0.9.2
