PT-2026-40117 · Red Hat · Red Hat Openshift
CVE-2026-31230
·
Published
2026-05-12
·
Updated
2026-05-12
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adversarial Robustness Toolbox versions prior to 1.20.2
Description
A command-line argument injection flaw exists in the Kubeflow component (specifically within
robustness evaluation fgsm pytorch.py) of the Adversarial Robustness Toolbox. The issue stems from the unsafe use of the eval() function, which is used to parse string values provided through the --clip values and --input shape arguments. A remote attacker who can control these arguments, such as through automated scripts or pipeline configurations, can inject arbitrary Python code, resulting in arbitrary code execution on the system performing the evaluation.Recommendations
Update to version 1.20.2 or later.
As a temporary mitigation, avoid providing untrusted input to the
--clip values and --input shape arguments.Fix
Code Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Openshift