CVE-2026-55563: Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te
Summary
Feast, an open source tool for storing features (data used to train AI models), had a security flaw in versions before 0.65.0 in its GitHub workflow configuration. The flaw allowed a contributor from a forked repository to run their modified code with access to sensitive credentials (authentication tokens for GCP, AWS, and Snowflake cloud services), potentially letting them steal those credentials or access cloud resources they shouldn't reach.
Solution / Mitigation
This issue is fixed in version 0.65.0.
Vulnerability Details
EPSS: 0.0%
September 21, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55563
First tracked: September 21, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%