Vulnerability  ·  2026-10-05

Amazon SageMaker Distribution: OS command injection in Studio Space startup lets a project contributor run code in another member's Space and steal execution-role credentials

VulnerabilityHigh impactGlobalCVE-2026-104019
AWS disclosed CVE-2026-104019 on 2026-10-02 (NVD CVSS 9.0 v3.1 / 9.3 v4.0, Critical) for an OS command injection (CWE-78) in the SageMaker Distribution Studio Space startup validation script used by Amazon SageMaker Unified Studio. A crafted connection resource property is interpolated into a shell invocation without neutralization, letting an authenticated project contributor execute arbitrary commands in another project member's Studio Space and obtain that member's temporary execution-role credentials. The bulletin is in-window for this digest.
SageMaker Unified Studio is core ML infrastructure for a large share of AWS-based ML teams. The flaw crosses the project-member trust boundary in a managed AI/ML platform: a lower-privileged contributor can achieve code execution in a colleague's compute space and, critically for AI deployments, exfiltrate that member's execution-role credentials, giving the attacker the victim's access to data stores, models and downstream AWS services. Cross-tenant credential theft in managed ML compute is an act-today item.
A contributor crafts a connection resource property that is interpolated un-neutralized into a shell invocation in the Studio Space startup validation script. When the victim's Space starts or restarts, the injected command executes with the Space's permissions, enabling arbitrary code execution and, under Trusted Identity Propagation, theft of the victim member's temporary execution-role credentials for lateral access to the victim's AWS resources.
Amazon SageMaker Distribution 2.x < 2.14.12, 3.x < 3.9.12, 4.0.x < 4.0.11, 4.1.x < 4.1.11, 4.2.x < 4.2.8, 4.3.x < 4.3.5, 4.4.x < 4.4.3 (as used by SageMaker Unified Studio)
Upgrade to patched minor lines: 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, or 4.4.3 (4.5.x unaffected). In SageMaker Unified Studio, Spaces adopt the latest patch of their minor line on restart once patched images are deployed - restart affected Spaces. AWS bulletin: https://aws.amazon.com/security/security-bulletins/2026-125-aws/ ; GHSA-w64x-664p-7w66.
AWS security bulletin 2026-125NVD CVE-2026-104019GitHub advisory GHSA-w64x-664p-7w66Coverage (AWS fixes Loom and SageMaker flaws)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →