rpyc is vulnerable to Remote Code Execution (RCE)
80
High Risk
A Remote Code Execution (RCE) vulnerability was discreetly patched in version 6.0.0 of rpyc. This exploit is only possible when the server-side accesses the __array__ attribute and invokes it, such as through np.array(x).
You are affected by this flaw if you use a version >= 4.0.0 and = 5.3.1 of this package.
rpyc is vulnerable to Remote Code Execution (RCE) in versions 4.0.0 - 5.3.1.
To fix, upgrade to rpyc 6.0.0 or above.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant