Safety vulnerability ID: 76189
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized.
Latest version: 0.19.12
Kedro helps you build production-ready data and analytics pipelines
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application