Skip to content
qlibGHSA-hjr4-fhgp-23g9

qlib Deserialization of Untrusted Data vulnerability

Medium6.6CVE-2021-23338 · Published May 24, 2022 · updated Oct 14, 2024

This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

GitHub advisory

Affected versions

PackageAffectedFixed in
pyqlib
PyPI
< 0.7.00.7.0
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.