Skip to content
KedroGHSA-rm69-wvpv-r2w7

Kedro allows Remote Code Execution by Pulling Micro Packages

High8.8CVE-2024-12215 · Published Mar 20, 2025 · updated Jul 7, 2026

In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.

GitHub advisory

Affected versions

PackageAffectedFixed in
kedro
PyPI
<= 0.19.8No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-829, CWE-94
Also known as
CVE-2024-12215, PYSEC-2026-1485

More Kedro advisories

All Kedro
Advisory
Kedro has Arbitrary Code Execution via Malicious Logging Configuration
Critical9.8Apr 3
Kedro: Path Traversal in versioned dataset loading via unsanitized version string
High7.1Apr 3
Kedro deserialization vulnerability
Critical9.8Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.