adversarial-robustness-toolbox: kubeflow: Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input
Published May 12, 2026
9.8
CRITICALCVSS 3.1
EPSS 1.07%
Description
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe eval() function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters without any sanitization or security restrictions. An attacker can exploit this by providing a specially crafted string that contains arbitrary Python code, which will be executed when eval() is called, leading to complete compromise of the system running the ART evaluation.
Affected products
No data.
No data.
No data.
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-agent-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-controller-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-router-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kserve-storage-initializer-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-agent-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-controller-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-router-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kserve-storage-initializer-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important remote code execution flaw in the Adversarial Robustness Toolbox (ART) Kubeflow component, as deployed in Red Hat OpenShift AI. The vulnerability arises from the unsafe use of `eval()` on unsanitized user-supplied strings within the robustness evaluation function for PyTorch models. An attacker can leverage this to execute arbitrary Python code, leading to a complete compromise of the affected system.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-31228 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2476522 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29511 Advisory
- https://github.com/Trusted-AI/adversarial-robustness-toolbox
- https://nvd.nist.gov/vuln/detail/CVE-2026-31228
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31228.json
- https://www.cve.org/CVERecord?id=CVE-2026-31228
- https://www.notion.so/CVE-2026-31228-35d1e1393188817f9ab0dc4b1651dfe9
Change history (0)
No recorded changes yet.