Skip to content
scikit-learnGHSA-jw8x-6495-233v

scikit-learn sensitive data leakage vulnerability

Medium5.3CVE-2024-5206 · Published Jun 6, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
scikit-learn
PyPI
< 1.5.01.5.0
Details and references

A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset of tokens required for the TF-IDF technique to function. This behavior leads to the potential leakage of sensitive information, as the `stop_words_` attribute could contain tokens that were meant to be discarded and not stored, such as passwords or keys. The impact of this vulnerability varies based on the nature of the data being processed by the vectorizer.

CVSS 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-921, CWE-922
Also known as
CVE-2024-5206, PYSEC-2024-110

More scikit-learn advisories

All scikit-learn
DateAdvisory
May 242022scikit-learn Denial of Service
CVE-2020-28975High7.5fixed in 1.0.1
May 242022scikit-learn Deserialization of Untrusted Data
CVE-2020-13092Critical9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.