Skip to content
joblibGHSA-6hrg-qmvc-2xh8

joblib vulnerable to arbitrary code execution

Critical9.8CVE-2022-21797 · Published Sep 27, 2022 · updated Feb 14, 2025

The package joblib from 0 and before 1.2.0 is vulnerable to Arbitrary Code Execution via the `pre_dispatch` flag in `Parallel()` class due to the `eval()` statement.

GitHub advisory

Affected versions

PackageAffectedFixed in
joblib
PyPI
< 1.2.01.2.0
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.