HIGH8.8
PYSEC-2026-1485
Kedro allows Remote Code Execution by Pulling Micro Packages
Details
In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/kedro
Introduced in:
0No fixed version published yet for kedro (pip). Pin to a known-safe version or switch to an alternative.