model-serving-security
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecurityexamples/insecure-serving.json
MEDIUMSecurityMEDIUM
examples/insecure-serving.json
No direct evidence of embedded malware in this configuration fragment. The primary finding is severe security misconfiguration: a public unauthenticated inference endpoint served over plain HTTP combined with a privileged, root-running container, both of which materially increase the likelihood and impact of compromise or abuse. Additionally, using model version 'latest' adds version/supply-chain drift risk. This should be reviewed and hardened (auth required, HTTPS, network restrictions, and least-privilege container settings; pin model versions).
Confidence: 70%Severity: 86%
Audit Metadata