kedro is vulnerable to Remote Code Execution (RCE)
91
Critical Risk
Affected versions of the package are vulnerable to Remote Code Execution (RCE) through malicious shelve file uploads in Kedro's ShelveStore. Attackers can exploit this vulnerability by uploading a specially crafted file, which may execute arbitrary code on the server when processed.
You are affected if you are using a version that falls within the vulnerable range.
kedro is vulnerable to Remote Code Execution (RCE) in versions 0.18.4 - 0.19.8.
Upgrade the kedro library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant