Repository navigation
[GHSA-5r2p-pjr8-7fh7] SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality - #9905
Conversation
|
Hi there @mufaddal-rohawala! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
2606d7c
into
fahran-wallace/advisory-improvement-9905
|
Hi @fahran-wallace! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
Affected version range should exclude the SageMaker Python SDK v2.x
line -- the vulnerable code was never present there.
GHSA-5r2p-pjr8-7fh7 describes an unsafe eval() in the search_hub()
function of the sagemaker.core.jumpstart.search module, patched in
SageMaker Python SDK 3.4.0 (aws/sagemaker-python-sdk PR #5497). The
advisory's vulnerable_version_range is "< 3.4.0", which reads as
covering all 2.x releases too. That is not accurate.
This is not a case of a pre-existing feature being newly discovered as
unsafe: the JumpStart hub-search feature itself did exist in SDK v2.x
(as list_jumpstart_models(), backed by sagemaker/jumpstart/filters.py's
Operator/And/Or/Not/Identity classes), but that implementation's string
parser (parse_filter_string()) has always used plain str.split() on
known operator tokens -- never eval() -- at any point in its history.
The vulnerable module (sagemaker.core.jumpstart.search, with its
eval()-based query parser) was introduced from scratch as part of the
V3 rewrite. Per aws/sagemaker-python-sdk's git history, that file has
exactly one commit before the fix: its creation commit, dated
2025-11-20 and titled "Release PySDK V3" -- it did not exist before
that point. That module ships in the separate sagemaker-core PyPI
package, first appearing in sagemaker-core 2.0 (also released
2025-11-20) and remaining unsafe through 2.3.1; sagemaker-core 2.4.0
(released 2026-01-22, the day after the fix PR merged) replaced it with
a safe recursive-descent parser (search_public_hub_models()).
The sagemaker (SDK) package has depended on sagemaker-core<2.0.0 for
its entire 2.x lifetime, including 2.257.6, the last 2.x release
before the 3.0 cutover. No 2.x release of the sagemaker SDK, at any
point, could resolve to a sagemaker-core version containing this
module: it did not exist for any release before 2025-11-20, and every
2.x SDK release's own dependency ceiling excludes the >=2.0
sagemaker-core line it lives in afterward.
Requesting the affected range be corrected to accurately scope this to
SDK v3.x only (e.g. ">=3.0.0, <3.4.0"), so version-based scanners stop
flagging 2.x installs that cannot contain this vulnerability.