Back

CRITICAL

adversarial-robustness-toolbox: kubeflow: Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input

Published May 12, 2026

Description

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe eval() function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters without any sanitization or security restrictions. An attacker can exploit this by providing a specially crafted string that contains arbitrary Python code, which will be executed when eval() is called, leading to complete compromise of the system running the ART evaluation.

Affected products

Remediation

Red Hat statement

This is an Important remote code execution flaw in the Adversarial Robustness Toolbox (ART) Kubeflow component, as deployed in Red Hat OpenShift AI. The vulnerability arises from the unsafe use of `eval()` on unsanitized user-supplied strings within the robustness evaluation function for PyTorch models. An attacker can leverage this to execute arbitrary Python code, leading to a complete compromise of the affected system.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 12, 2026
Updated Aug 12, 2026
Reserved Mar 9, 2026
CISA Vulnrichment
Updated May 13, 2026
NVD
Status Awaiting Analysis
Modified Aug 12, 2026
Red Hat
Severity Important
Public date May 12, 2026
ENISA EUVD
Assigner mitre
Published May 12, 2026
Updated Aug 12, 2026
Exploited since n/a
EUVD-2026-29511