VDB
Sign up
HIGH8.8

PYSEC-2026-1485

Kedro allows Remote Code Execution by Pulling Micro Packages

Details

In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/kedro
Introduced in: 0

No fixed version published yet for kedro (pip). Pin to a known-safe version or switch to an alternative.

References