VAITP Dataset

← Back to the dataset

CVE-2026-83551

Cleartext HMAC key stored in SageMaker pipeline decorators enables forged signatures and code execution.

  • CVSS 8.5
  • 312
  • Cryptographic
  • Remote

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.

CWE
312
CVSS base score
8.5
Published
2026-09-01
OWASP
A02 Cryptographic Failures
Orthogonal defect classification
Assignment
Code defect classification
Incorrect Assignment
Category
Cryptographic
Subcategory
Cryptographic Implementation Error
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Affected component
Amazon SageMaker Python SDK
Fixed by upgrading
Yes

Solution

Upgrade the Amazon SageMaker Python SDK to v3.11.0 or newer (or v2.256.0 or newer).

Vulnerable code sample

import json
from sagemaker.workflow.pipeline import Pipeline
from sagemaker.workflow.steps import step, remote

@step
def my_step(input_uri: str):
    # VULNERABLE: stores HMAC signing key in cleartext step metadata
    signing_key = "hmac-secret-key-0123"
    payload = {"input_uri": input_uri, "signing_key": signing_key}
    return json.dumps(payload)

pipeline = Pipeline(
    name="example-pipeline",
    steps=[my_step],
    description="Demo pipeline with vulnerable step"
)

Patched code sample

import json
from sagemaker.workflow.pipeline import Pipeline
from sagemaker.workflow.steps import step, remote
from sagemaker.secrets_manager import SecretsManager

secrets = SecretsManager()

@step
def my_step(input_uri: str):
    # FIX: retrieve HMAC key from Secrets Manager instead of embedding it
    signing_key = secrets.get_secret_value(SecretId="my-hmac-key")["SecretString"]
    payload = {"input_uri": input_uri, "signing_key": signing_key}
    return json.dumps(payload)

pipeline = Pipeline(
    name="example-pipeline",
    steps=[my_step],
    description="Demo pipeline with patched step"
)

Payload

__VAITP_MODEL_REFUSED__

Cite this entry

@misc{vaitp:cve202683551,
  title        = {{Cleartext HMAC key stored in SageMaker pipeline decorators enables forged signatures and code execution.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-83551},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-83551/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::