Skip to content
scikit-learnGHSA-jjw5-xxj6-pcv5

scikit-learn Deserialization of Untrusted Data

Critical9.8CVE-2020-13092 · Published May 24, 2022 · updated Oct 22, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
scikit-learn
PyPI
<= 0.23.0No fix yet
Details and references

scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the `joblib.load()` function, if `__reduce__` makes an `os.system call`. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2020-13092, PYSEC-2020-107

More scikit-learn advisories

All scikit-learn
DateAdvisory
May 242022scikit-learn Denial of Service
CVE-2020-28975High7.5fixed in 1.0.1
Jun 62024scikit-learn sensitive data leakage vulnerability
CVE-2024-5206Medium5.3fixed in 1.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.