Oddbean new post about | logout
 Ah, this'll go well.

TorchServe, a production server for machine learning framework PyTorch, exposes its management console to the world in default config with what looks like multiple paths to remote command execution.

https://www.oligo.security/blog/shelltorch-torchserve-ssrf-vulnerability-cve-2023-43654