← Replicate

2024 Replicate — critical RCE vulnerability (Cog format)

2024 Unknown records affected Share on X

Data compromised

Potential access to private AI models, proprietary data, personal information

Technical writeup

Replicate patched a critical remote code execution (RCE) vulnerability that could have allowed attackers to access private AI models and sensitive data. Researchers found that malicious containers in Replicate's proprietary Cog format could execute code with root privileges and access customer data across the platform, including proprietary knowledge and personal information. The flaw was disclosed and patched.

Root cause

Critical RCE vulnerability in Cog container format

References