CVE-2026-90614: Fedml-Ai Fedml
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
- Fedml-Ai Fedml: version 0.9.0 only; version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 0.9.5 only; …
Published 2026-09-14. Last modified 2026-09-14.