Skip to content
pandasPYSEC-2020-73

** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's

Critical9.8CVE-2020-13091 · Published May 15, 2020 · updated Nov 8, 2023

Source advisory

Affected versions

PackageAffectedFixed in
pandas
PyPI
< 1.0.41.0.4

Changes since it was listed

DateChange
Sep 24Severity: Unrated to Critical
Details and references

** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
NVD
Also known as
CVE-2020-13091

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.