A set of critical vulnerabilities called “ShellTorch” in the open-source tool for serving AI models affects tens of thousands of servers accessible to the internet, some of which belong to large organizations.
See also: BEC attacks in healthcare sector increased by 279%

TorchServe, maintained by Meta and Amazon, is a popular tool for provisioning and scaling PyTorch (a machine learning framework) models in production. The library is primarily used by those involved in training and developing AI models, from researchers in academia to large companies such as Amazon, OpenAI, Tesla, Azure, Google, and Intel.
The role of ShellTorch in AI servers is to provide a secure environment for executing AI code. This means that ShellTorch provides a secure and isolated platform for executing code, protecting the server from potential attacks and exploits. By using ShellTorch, AI servers can execute AI code safely and avoid potential vulnerabilities. This is especially important because AI code may contain sensitive information or require high computational demands, and therefore must be protected from unwanted access or malicious attacks.
The TorchServe vulnerabilities discovered by the Oligo security team can lead to unauthorized access to servers and remote code execution (RCE) on vulnerable devices. The three vulnerabilities are collectively called ShellTorch and affect TorchServe versions 0.3.0 to 0.8.1.
The first flaw is an unauthenticated suppressive API configuration interface that results in the web panel being connected to the IP address 0.0.0.0 instead of localhost, exposing it to external requests. Since the interface lacks authentication, it allows unrestricted access to any user, which can be used to upload malicious models from an external address.
See also: GitHub Dependabot: Spoofed in hundreds of successful attacks

The second issue, tracked as CVE-2023-43654, is a remote server request forgery (SSRF) that, if exploited as part of a chain of exploits, could lead to remote code execution (RCE). Although the TorchServe API has logic for an allowed list of domains for downloading model configuration files from a remote URL, it was found that all domains are selected by default, causing an SSRF flaw. This allows attackers to upload malicious models that trigger arbitrary code execution when launched on the targeted server.
The third vulnerability, detected as CVE-2022-1471, is a Java that leads to remote code execution. Due to unsafe deserialization in the SnakeYAML library, attackers can upload a model with a malicious YAML file to enable remote code execution.
It should be noted that Oligo did not discover the SnakeYAML vulnerability, but used it as part of its exploit chain. The researchers warn that if an attacker combines the above vulnerabilities, they can easily compromise a system running vulnerable versions of TorchServe.
To fix these ShellTorch vulnerabilities, users should upgrade to TorchServe 0.8.2, released on August 28, 2023. This update displays a warning about the SSRF issue to the user, effectively resolving the risk from CVE-2023-43654.
Then, correctly configure the management console management_address to https://127.0.0.1:8081 in the config.properties file. This will make TorchServe connect to the computer locally instead of to any IP address configured on the server.
See also: Ransomware attacks in the education sector increased in August
Finally, make sure your server only retrieves models from trusted domains by updating allowed_urls in the config.properties file accordingly.
