{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31228.json"
      }
    ],
    "title": "adversarial-robustness-toolbox: kubeflow: Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input",
    "tracking": {
      "current_release_date": "2026-08-12T04:24:51+00:00",
      "generator": {
        "date": "2026-08-12T04:24:51+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.14"
        }
      },
      "id": "CVE-2026-31228",
      "initial_release_date": "2026-05-12T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-05-12T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-10T11:00:52.758843+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-12T04:24:51+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift AI (RHOAI)",
                "product": {
                  "name": "Red Hat OpenShift AI (RHOAI)",
                  "product_id": "red_hat_openshift_ai_(rhoai)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_ai"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift AI (RHOAI)"
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-kserve-agent-rhel9",
            "product": {
              "name": "rhoai/odh-kserve-agent-rhel9",
              "product_id": "rhoai/odh-kserve-agent-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-kserve-agent-rhel9?repository_url=registry.redhat.io/rhoai/odh-kserve-agent-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-kserve-controller-rhel9",
            "product": {
              "name": "rhoai/odh-kserve-controller-rhel9",
              "product_id": "rhoai/odh-kserve-controller-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-kserve-controller-rhel9?repository_url=registry.redhat.io/rhoai/odh-kserve-controller-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-kserve-router-rhel9",
            "product": {
              "name": "rhoai/odh-kserve-router-rhel9",
              "product_id": "rhoai/odh-kserve-router-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-kserve-router-rhel9?repository_url=registry.redhat.io/rhoai/odh-kserve-router-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoai/odh-kserve-storage-initializer-rhel9",
            "product": {
              "name": "rhoai/odh-kserve-storage-initializer-rhel9",
              "product_id": "rhoai/odh-kserve-storage-initializer-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/odh-kserve-storage-initializer-rhel9?repository_url=registry.redhat.io/rhoai/odh-kserve-storage-initializer-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-kserve-agent-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-agent-rhel9"
        },
        "product_reference": "rhoai/odh-kserve-agent-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-kserve-controller-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-controller-rhel9"
        },
        "product_reference": "rhoai/odh-kserve-controller-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-kserve-router-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-router-rhel9"
        },
        "product_reference": "rhoai/odh-kserve-router-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoai/odh-kserve-storage-initializer-rhel9 as a component of Red Hat OpenShift AI (RHOAI)",
          "product_id": "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-storage-initializer-rhel9"
        },
        "product_reference": "rhoai/odh-kserve-storage-initializer-rhel9",
        "relates_to_product_reference": "red_hat_openshift_ai_(rhoai)"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-31228",
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "discovery_date": "2026-05-12T16:01:53.808312+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-agent-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-controller-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-router-rhel9"
          ]
        },
        {
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-storage-initializer-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2476522"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Adversarial Robustness Toolbox (ART), specifically within its Kubeflow component. The robustness evaluation function for PyTorch models uses the `eval()` function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters without proper sanitization. A remote attacker can exploit this by providing a specially crafted string containing arbitrary Python code, leading to remote code execution and complete compromise of the system running the ART evaluation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "adversarial-robustness-toolbox: kubeflow: Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important remote code execution flaw in the Adversarial Robustness Toolbox (ART) Kubeflow component, as deployed in Red Hat OpenShift AI. The vulnerability arises from the unsafe use of `eval()` on unsanitized user-supplied strings within the robustness evaluation function for PyTorch models. An attacker can leverage this to execute arbitrary Python code, leading to a complete compromise of the affected system.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-agent-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-controller-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-router-rhel9",
          "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-storage-initializer-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-31228"
        },
        {
          "category": "external",
          "summary": "RHBZ#2476522",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476522"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-31228",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-31228"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-31228",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31228"
        },
        {
          "category": "external",
          "summary": "https://github.com/Trusted-AI/adversarial-robustness-toolbox",
          "url": "https://github.com/Trusted-AI/adversarial-robustness-toolbox"
        },
        {
          "category": "external",
          "summary": "https://www.notion.so/CVE-2026-31228-35d1e1393188817f9ab0dc4b1651dfe9",
          "url": "https://www.notion.so/CVE-2026-31228-35d1e1393188817f9ab0dc4b1651dfe9"
        }
      ],
      "release_date": "2026-05-12T00:00:00+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-agent-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-controller-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-router-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-storage-initializer-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-agent-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-controller-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-router-rhel9",
            "red_hat_openshift_ai_(rhoai):rhoai/odh-kserve-storage-initializer-rhel9"
          ]
        }
      ],
      "title": "adversarial-robustness-toolbox: kubeflow: Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input"
    }
  ]
}