KedroGHSA-rm69-wvpv-r2w7
Kedro allows Remote Code Execution by Pulling Micro Packages
High8.8CVE-2024-12215 · Published Mar 20, 2025 · updated Jul 7, 2026
In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| kedro PyPI | <= 0.19.8 | No fix yet |
Details and references
More Kedro advisories
All Kedro| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 3 | Kedro has Arbitrary Code Execution via Malicious Logging Configuration | Critical9.8 | 1.3.0 |
| Apr 3 | Kedro: Path Traversal in versioned dataset loading via unsanitized version string | High7.1 | 1.3.0 |
| Mar 202025 | Kedro deserialization vulnerability | Critical9.8 | 0.19.9 |