PyPI: sagemaker

CVE-2026-8597

Safety vulnerability ID: SFTY-20260521-99051

Safety legacy ID: pyup.io-98667

Affected versions of the sagemaker package are vulnerable to Insecure Deserialisation due to the ModelBuilder Triton inference handler deserialising model artifacts without performing integrity verification. The Triton handler loads artifacts retrieved from the configured S3 model artifact path through Python pickle without first validating their integrity, allowing tampered artifacts to be unpickled during container lifecycle events. A remote authenticated actor with S3 write access to the model artifact path can replace a model file with a crafted pickle payload that executes on the next container start, achieving Remote Code Execution under the SageMaker execution role's IAM permissions.

Created at: May 21, 2026Updated at: May 21, 2026

Overview

Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler

Advisory

Affected versions of the sagemaker package are vulnerable to Insecure Deserialisation due to the ModelBuilder Triton inference handler deserialising model artifacts without performing integrity verification. The Triton handler loads artifacts retrieved from the configured S3 model artifact path through Python pickle without first validating their integrity, allowing tampered artifacts to be unpickled during container lifecycle events. A remote authenticated actor with S3 write access to the model artifact path can replace a model file with a crafted pickle payload that executes on the next container start, achieving Remote Code Execution under the SageMaker execution role's IAM permissions.

Affected Package

Affecting sagemaker package, versions
>=2.199.0,<=2.257.1
>=3.0.0,<=3.7.1

Also affects

---

How to Fix

Upgrade
sagemaker
to
2.257.2
3.8.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more