nemo-toolkit is vulnerable to Unsafe Deserialization
88
High Risk
Affected versions of this package contain multiple paths to arbitrary code execution in model handling: pickle data is deserialized without restricting which classes are loaded, and a command-line option is interpreted directly as Python code at runtime.
You are affected if you are using a version that falls within the vulnerable range.
nemo-toolkit is vulnerable to Unsafe Deserialization in versions 0.0.1 - 2.7.2.
Upgrade the nemo-toolkit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant