{"id":"CVE-2024-34073","aliases":["GHSA-7pc3-pr3q-58vg","PYSEC-2026-1887"],"title":"sagemaker-python-sdk Command Injection vulnerability","summary":"sagemaker-python-sdk Command Injection vulnerability","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"sagemaker","product":"sagemaker","ecosystem":"pip","affected":["sagemaker < 2.214.3"],"patched":["sagemaker 2.214.3"],"published":"2024-05-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:13.557676374Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7pc3-pr3q-58vg","references":[{"url":"https://github.com/aws/sagemaker-python-sdk/security/advisories/GHSA-7pc3-pr3q-58vg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34073"},{"url":"https://github.com/aws/sagemaker-python-sdk/pull/4556"},{"url":"https://github.com/aws/sagemaker-python-sdk/commit/2d873d53f708ea570fc2e2a6974f8c3097fe9df5"},{"url":"https://github.com/aws/sagemaker-python-sdk"}],"tags":["osv","pip"],"epss":0.01153,"epssPercentile":0.65101,"ingestedAt":"2026-07-08T18:25:47.058Z","slug":"CVE-2024-34073","body":"## Overview\n\n### Impact\n\nThe capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module before version 2.214.3 allows for potentially unsafe Operating System (OS) Command Injection if inappropriate command is passed as the “requirements_path” parameter. This consequently may allow an unprivileged third party to cause remote code execution, denial of service, affecting both confidentiality and integrity.\n\nImpacted versions: <2.214.3\n\n### Credit\n\nWe would like to thank HiddenLayer for collaborating on this issue through the coordinated vulnerability disclosure process.\n\n### Workarounds\n\nDo not override the “requirements_path” parameter of capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils`, instead use the default value.\n\n### References\n\nIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.\n[1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting\n\nFixed by: https://github.com/aws/sagemaker-python-sdk/pull/4556\n\n## Affected packages\n\n- `sagemaker < 2.214.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `sagemaker 2.214.3`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}