{"data":{"id":"794561e9-f195-47a7-b2e8-5c8c4b025de6","title":"CVE-2026-55563: Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te","summary":"Feast, an open source tool for storing features (data used to train AI models), had a security flaw in versions before 0.65.0 in its GitHub workflow configuration. The flaw allowed a contributor from a forked repository to run their modified code with access to sensitive credentials (authentication tokens for GCP, AWS, and Snowflake cloud services), potentially letting them steal those credentials or access cloud resources they shouldn't reach.","solution":"This issue is fixed in version 0.65.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55563","publishedAt":"2026-09-21T16:17:09.390Z","cveId":"CVE-2026-55563","cweIds":["CWE-863"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Feast"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-21T16:17:09.390Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}