HiddenLayer, a Gartner recognized Cool Vendor for AI Security, is the leading provider of Security for AI. Its security platform helps enterprises safeguard the machine learning models behind their most important products. HiddenLayer is the only company to offer turnkey security for AI that does not add unnecessary complexity to models and does not require access to raw data and algorithms. Founded by a team with deep roots in security and ML, HiddenLayer aims to protect enterprise’s AI from inference, bypass, extraction attacks, and model theft. The company is backed by a group of strategic investors, including M12, Microsoft’s Venture Fund, Moore Strategic Ventures, Booz Allen Ventures, IBM Ventures, and Capital One Ventures.
Security Advisory
HiddenLayer’s Synaptic Adversarial Intelligence (SAI) team consists of multidisciplinary cybersecurity experts and data scientists dedicated to raising awareness about threats to machine learning and artificial intelligence systems. Our mission is to educate data scientists, MLDevOps teams, and cybersecurity practitioners on evaluating ML/AI vulnerabilities and risks, promoting more security-conscious implementations and deployments.
During our research, we identify numerous vulnerabilities within ML/AI projects. While our research blogs cover those that we consider to be most impactful, some affect only specific projects or use cases. We’ve therefore created this dedicated space to share all of our findings, enabling users within our community to keep updated on new vulnerabilities, including security issues that have not been assigned a CVE.
December 2024
-
SAI-ADV-2024-004 keras.models.load_model when scanning .h5 files leads to arbitrary code execution December 16, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
SAI-ADV-2024-005 keras.models.load_model when scanning .pb files leads to arbitrary code execution December 16, 2024
A vulnerability exists inside the unsafe_check_h5 function within the watchtower/src/utils/model_inspector_util.py file. This function runs keras.models.load_model on the .h5 file the user wants to scan for malicious payloads. A maliciously crafted .h5 file will execute its payload when run with keras.models.load_model, allowing for a user’s device to be compromised when scanning a downloaded file.
October 2024
-
NVIDIA NeMo
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
September 2024
-
CVE-2024-45858 Eval on XML parameters allows arbitrary code execution when loading RAIL file September 18, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-27321 Eval on CSV data allows arbitrary code execution in the MLCTaskValidate class September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-27320 Eval on CSV data allows arbitrary code execution in the ClassificationTaskValidate class September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45857 Unsafe deserialization in Datalab leads to arbitrary code execution September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45846 Eval on query parameters allows arbitrary code execution in Weaviate integration September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45847 Eval on query parameters allows arbitrary code execution in Vector Database integrations September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45848 Eval on query parameters allows arbitrary code execution in ChromaDB integration September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45849 Eval on query parameters allows arbitrary code execution in SharePoint integration list creation September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45850 Eval on query parameters allows arbitrary code execution in SharePoint integration site column creation September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45851 Eval on query parameters allows arbitrary code execution in SharePoint integration list item creation September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MindsDB
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45853 Pickle Load on inhouse BYOM model prediction leads to arbitrary code execution September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45854 Pickle Load on inhouse BYOM model describe query leads to arbitrary code execution September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-45855 Pickle Load on inhouse BYOM model finetune leads to arbitrary code execution September 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MindsDB
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
August 2024
-
SAI-ADV-2024-002 Exec on untrusted LLM output leading to arbitrary code execution on Evaporate integration August 30, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
SAI-ADV-2024-003 Exec on untrusted LLM output leading to arbitrary code execution on Evaporate integration August 12, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
July 2024
-
Wyze Cam V4
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
Tensorflow Probability
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
June 2024
-
Skops
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
YData-profiling
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-37056 Cloudpickle Load on LightGBM SciKit Learn Model Leading to Code Execution June 4, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
MLflow
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
YData-profiling
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
YData-profiling
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
April 2024
-
AWS Sagemaker
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-34072 Numpy defaults to allowing Pickle to be run when content type is NPY or NPZ April 30, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
R
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
February 2024
-
ONNX
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-27318 Path sanitization bypass leading to arbitrary read February 23, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
ClearML
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-24595 Credentials Stored in Plaintext in MongoDB Instance February 1, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-24594 Web Server Renders User HTML Leading to XSS February 1, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-24593 Cross-site Request Forgery in ClearML Server February 1, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-24592 Improper Auth Leading to Arbitrary Read-Write Access February 1, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...
-
CVE-2024-24590 Pickle Load on Artifact Get Leading to Code Execution February 1, 2024
Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...