Threat Advisory

ShellTorch Flaws Expose AI Servers to Code Execution Attacks

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researcher has discovered a critical vulnerability, collectively known as ShellTorch, have been found in the open-source TorchServe AI model-serving tool, affecting versions 0.3.0 through 0.8.1. These flaws expose tens of thousands of internet-exposed servers, including those of major organizations. The vulnerabilities include an unauthenticated management interface API misconfiguration that allows unrestricted access and the upload of malicious models, a remote server-side request forgery (SSRF) flaw that can lead to remote code execution, and a Java deserialization issue that allows attackers to trigger remote code execution using malicious YAML files. A free checker tool has also been released to identify vulnerable instances. Meta and Amazon have already patched these issues, emphasizing the importance of using the latest version of TorchServe.[/subscribe_to_unlock_form]

Summary:

Researcher has discovered a critical vulnerability, collectively known as ShellTorch, have been found in the open-source TorchServe AI model-serving tool, affecting versions 0.3.0 through 0.8.1. These flaws expose tens of thousands of internet-exposed servers, including those of major organizations. The vulnerabilities include an unauthenticated management interface API misconfiguration that allows unrestricted access and the upload of malicious models, a remote server-side request forgery (SSRF) flaw that can lead to remote code execution, and a Java deserialization issue that allows attackers to trigger remote code execution using malicious YAML files. A free checker tool has also been released to identify vulnerable instances. Meta and Amazon have already patched these issues, emphasizing the importance of using the latest version of TorchServe.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you upgrade Torch Serve to version 0.8.2.

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/shelltorch-flaws-expose-ai-servers-to-code-execution-attacks/

[/emaillocker]
crossmenu