—
PYSEC-2024-44
Quick fix
PYSEC-2024-44 — rpyc: upgrade to the fixed version with the command below.
pip install --upgrade 'rpyc>=6.0.0'Details
In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
Are you affected?
Enter the version of the package you're using.