Security Advisory

HiddenLayer’s Synaptic Adversarial Intelligence (SAI) team consists of multidisciplinary cybersecurity experts and data scientists dedicated to raising awareness about threats to machine learning and artificial intelligence systems. Our mission is to educate data scientists, MLDevOps teams, and cybersecurity practitioners on evaluating ML/AI vulnerabilities and risks, promoting more security-conscious implementations and deployments.

During our research, we identify numerous vulnerabilities within ML/AI projects. While our research blogs cover those that we consider to be most impactful, some affect only specific projects or use cases. We’ve therefore created this dedicated space to share all of our findings, enabling users within our community to keep updated on new vulnerabilities, including security issues that have not been assigned a CVE.

December 2024

October 2024

September 2024

August 2024

July 2024

  • Wyze Cam V4

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • Tensorflow Probability

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More

June 2024

  • Skops

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • YData-profiling

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • MLflow

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • YData-profiling

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • YData-profiling

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More

April 2024

February 2024

  • ONNX

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ONNX

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More
  • ClearML

    Crafted WiFI network name (SSID) leads to arbitrary command injection CVE Number CVE-2024-37066 Summary The net_service_thread function in libwyzeUtilsPlatform.so spawns a shell command containing a user-specified WiFi network name (SSID) in an unsafe way, which can lead to arbitrary command injection as root during...

    Read More