Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical9.8CVE-2026-35171 · Published Apr 3, 2026 · updated Jun 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| kedro PyPI | < 1.3.0 | 1.3.0 |
Details and references
### Impact This is a **critical remote code execution (RCE)** vulnerability caused by unsafe use of `logging.config.dictConfig()` with user-controlled input. Kedro allows the logging configuration file path to be set via the `KEDRO_LOGGING_CONFIG` environment variable and loads it without validation. The logging configuration schema supports the special `()` key, which enables arbitrary callable instantiation. An attacker can exploit this to execute arbitrary system commands during application startup. --- ### Patches The vulnerability is fixed by introducing validation that rejects the unsafe `()` factory key in logging configurations before passing them to `dictConfig()`. #### Fixed in - Kedro 1.3.0 Users should upgrade to this version as soon as possible. --- ### Workarounds If upgrading is not immediately possible: - Do not allow untrusted input to control the `KEDRO_LOGGING_CONFIG` environment variable - Restrict write access to logging configuration files - Avoid using externally supplied or dynamically generated logging configs - Manually validate logging YAML to ensure it does not contain the `()` key These mitigations reduce risk but do not fully eliminate it. --- ### References - Python logging configuration documentation: https://docs.python.org/3/library/logging.config.html#logging-config-dictschema - CWE-94: Code Injection , https://cwe.mitre.org/data/definitions/94.html
More Kedro advisories
All Kedro| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 3 | Kedro: Path Traversal in versioned dataset loading via unsanitized version string CVE-2026-35167High7.1fixed in 1.3.0 | High7.1 | 1.3.0 |
| Mar 202025 | Kedro deserialization vulnerability CVE-2024-9701Critical9.8fixed in 0.19.9 | Critical9.8 | 0.19.9 |
| Mar 202025 | Kedro allows Remote Code Execution by Pulling Micro Packages CVE-2024-12215High8.8no fix yet | High8.8 | No fix yet |