HIGH7.8
PYSEC-2026-1254
Cleanlab Deserialization of Untrusted Data vulnerability
Details
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/cleanlab
Introduced in:
2.4.0No fixed version published yet for cleanlab (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-45857[ADVISORY]
- https://github.com/cleanlab/cleanlab[PACKAGE]
- https://github.com/cleanlab/cleanlab/blob/v2.6.6/cleanlab/datalab/internal/serialize.py#L102-L138[WEB]
- https://hiddenlayer.com/sai-security-advisory/2024-09-cleanlab[WEB]
- https://pypi.org/project/cleanlab[PACKAGE]
- https://github.com/advisories/GHSA-8cm9-rrgc-4pcj[ADVISORY]