VDB
Sign up
MEDIUM

GHSA-mwgj-7x7j-6966

Deserialization of Untrusted Data in ParlAI

Quick fix

GHSA-mwgj-7x7j-6966 — parlai: upgrade to the fixed version with the command below.

pip install --upgrade 'parlai>=1.1.0'

Details

Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/parlai
Introduced in: 0Fixed in: 1.1.0
Fixpip install --upgrade 'parlai>=1.1.0'

References