Skip to finding
interesting · Cloud privilege

A SageMaker project contributor can execute commands in another member’s Studio Space and take that member’s temporary role credentials.

Affects

Amazon SageMaker Distribution images used by SageMaker Unified Studio Spaces in AWS.

Crafted project connection data reaches an unneutralized shell invocation when another member’s Space validates connections during startup.

Detail and 2 sources

The injected command runs in the peer’s Space; when Trusted Identity Propagation is enabled, it can obtain that member’s temporary execution-role credentials for downstream AWS calls.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026