PT-2026-40117 · Red Hat · Red Hat Openshift

CVE-2026-31230

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adversarial Robustness Toolbox versions prior to 1.20.2
Description A command-line argument injection flaw exists in the Kubeflow component (specifically within robustness evaluation fgsm pytorch.py) of the Adversarial Robustness Toolbox. The issue stems from the unsafe use of the eval() function, which is used to parse string values provided through the --clip values and --input shape arguments. A remote attacker who can control these arguments, such as through automated scripts or pipeline configurations, can inject arbitrary Python code, resulting in arbitrary code execution on the system performing the evaluation.
Recommendations Update to version 1.20.2 or later. As a temporary mitigation, avoid providing untrusted input to the --clip values and --input shape arguments.

Fix

Code Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31230

Affected Products

Red Hat Openshift