{"data":{"id":"62b4a52d-6221-4d85-b621-d657d22a4916","title":"CVE-2026-54745: Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the","summary":"Kubeflow Pipelines (a tool for building machine learning workflows) before version 2.17.0 has a server-side request forgery vulnerability (SSRF, a bug where an attacker tricks the server into making requests to internal systems it shouldn't access) in its frontend. An attacker can use the /_proxy/ route to make the server send requests to internal services and steal sensitive data like cloud credentials or Kubernetes API access, even without authentication.","solution":"Update to Kubeflow Pipelines version 2.17.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54745","publishedAt":"2026-08-28T20:18:17.240Z","cveId":"CVE-2026-54745","cweIds":["CWE-284","CWE-918"],"cvssScore":"10","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Kubeflow Pipelines"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-28T20:18:17.240Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}