Skip to content
KedroGHSA-747f-ww56-4q4h

Kedro deserialization vulnerability

Critical9.8CVE-2024-9701 · Published Mar 20, 2025 · updated Jul 6, 2026

A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized.

GitHub advisory

Affected versions

PackageAffectedFixed in
kedro
PyPI
< 0.19.90.19.9
Details and references

More Kedro advisories

All Kedro

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.