Kedro: Path Traversal in versioned dataset loading via unsanitized version string
High7.1CVE-2026-35167 · Published Apr 3, 2026 · updated Jun 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| kedro PyPI | < 1.3.0 | 1.3.0 |
Details and references
### Impact The `_get_versioned_path()` method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequences such as ../ are preserved and can escape the intended versioned dataset directory. This is reachable through multiple entry points: `catalog.load(..., version=...)`, `DataCatalog.from_config(..., load_versions=...)`, and the CLI via `kedro run --load-versions=dataset:../../../secrets`. An attacker who can influence the version string can force Kedro to load files from outside the intended version directory, enabling unauthorized file reads, data poisoning, or cross-tenant data access in shared environments. ### Patches Yes. Fixed in kedro version 1.3.0. Users should upgrade to kedro >= 1.3.0. ### Workarounds Validate version strings before passing them to DataCatalog or the CLI, ensuring they do not contain `..` segments, path separators, or absolute paths.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2026-35167, PYSEC-2026-71
More Kedro advisories
All Kedro| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 3 | Kedro has Arbitrary Code Execution via Malicious Logging Configuration CVE-2026-35171Critical9.8fixed in 1.3.0 | Critical9.8 | 1.3.0 |
| Mar 202025 | Kedro deserialization vulnerability CVE-2024-9701Critical9.8fixed in 0.19.9 | Critical9.8 | 0.19.9 |
| Mar 202025 | Kedro allows Remote Code Execution by Pulling Micro Packages CVE-2024-12215High8.8no fix yet | High8.8 | No fix yet |