Safety vulnerability ID: 54330
The information on this page was manually curated by our Cybersecurity Intelligence Team.
parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affected versions the package is vulnerable to YAML deserialization attack caused by unsafe loading which leads to Arbitary code execution. This security bug is patched by avoiding unsafe loader users should update to version above v1.1.0. If upgrading is not possible then users can change the Loader used to SafeLoader as a workaround. See commit 507d066ef432ea27d3e201da08009872a2f37725 for details.
Latest version: 1.7.2
Unified platform for dialogue research.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application