Description
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
Problem types
Product status
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
Timeline
| 2026-04-04: | Advisory disclosed |
| 2026-04-04: | VulDB entry created |
| 2026-04-04: | VulDB entry last update |
Credits
Ana10gy (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/355289 (VDB-355289 | FedML-AI FedML gRPC server grpc_server.py sendMessage deserialization)
vuldb.com/vuln/355289/cti (VDB-355289 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/782201 (Submit #782201 | FedML-AI FedML <= 0.8.9 Remote Code Execution)
github.com/AnalogyC0de/public_exp/issues/26