A set of critical vulnerabilities in the open source machine learning framework TorchServe have been discovered, which could allow cyberattackers to subvert AI models and access proprietary data. The bugs affect Amazon and Google’s machine learning services, among many others, and thousands of vulnerable instances of the software are publicly exposed on the Internet. All versions of TorchServe from 0.8.1 and earlier are vulnerable, and PyTorch has addressed the flaws in TorchServe version 0.8.2.