Exposure of Data Element to Wrong Session Affecting skypilot package, versions [,0.10.4)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-SKYPILOT-14860868
  • published5 Jan 2026
  • disclosed1 Jan 2026
  • creditUnknown

Introduced: 1 Jan 2026

CVE NOT AVAILABLE CWE-488  (opens in a new tab)

How to fix?

Upgrade skypilot to version 0.10.4 or higher.

Overview

skypilot is a SkyPilot: Run AI on Any Infra — Unified, Faster, Cheaper.

Affected versions of this package are vulnerable to Exposure of Data Element to Wrong Session in the form of allowing users to see the pending jobs belonging to other users, under some conditions, and leaking keys into an unintended config file. By not placing the user hash into the database at job queue time, the node exposes pending jobs to other uses. Additionally, keys belonging to a controller server are written into the API server config when it is started up. These keys may not be overwritten by subsequent request configs and may therefore be applied to unintended jobs.

CVSS Base Scores

version 4.0
version 3.1