TorchServeGHSA-xx7c-j7h3-vjcq
TorchServe script references S3 bucket without ensuring ownership or confirming accessibility
Medium6.3CVE-2024-6577 · Published Mar 20, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| torchserve PyPI | <= 0.11.0 | No fix yet |
Details and references
In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2024-6577, PYSEC-2026-1973
More TorchServe advisories
All TorchServe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 182024 | TorchServe gRPC Port Exposure CVE-2024-35199High8.2fixed in 0.11.0 | High8.2 | 0.11.0 |
| Jul 182024 | TorchServe vulnerable to bypass of allowed_urls configuration CVE-2024-35198Critical9.8fixed in 0.11.0 | Critical9.8 | 0.11.0 |
| Nov 212023 | TorchServe ZipSlip CVE-2023-48299Medium5.3fixed in 0.9.0 | Medium5.3 | 0.9.0 |
| Oct 22023 | TorchServe Server-Side Request Forgery vulnerability CVE-2023-43654Critical9.8fixed in 0.8.2 | Critical9.8 | 0.8.2 |
| Oct 22023 | TorchServe Pre-Auth Remote Code Execution GHSA-4mqg-h5jf-j9m7Critical9.9fixed in 0.8.2 | Critical9.9 | 0.8.2 |