VDB
Sign up
LOW2.5

PYSEC-2026-1288

DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables

Quick fix

PYSEC-2026-1288 — datachain: upgrade to the fixed version with the command below.

pip install --upgrade 'datachain>=0.34.2'

Details

The DataChain library reads serialized objects from environment variables (such as `DATACHAIN__METASTORE` and `DATACHAIN__WAREHOUSE`) in the `loader.py` module. An attacker with the ability to set these environment variables can trigger code execution when the application loads.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/datachain
Introduced in: 0Fixed in: 0.34.2
Fixpip install --upgrade 'datachain>=0.34.2'

References