PT-2026-94089 · Meta+1 · Pytorch+1

CVE-2026-62997

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions kedro-datasets versions 5.0.0 through 9.4.9
Description The kedro datasets experimental.pytorch.PyTorchDataset component loads .pt model files using the torch.load function without enforcing the weights only=True parameter, and it silently drops user-supplied load args. When used with PyTorch versions earlier than 2.6, this allows a malicious pickle-backed model—sourced from a compromised shared registry, downloaded checkpoint, or external source—to execute arbitrary code during the loading process in a Kedro pipeline. This issue specifically affects the opt-in kedro datasets experimental component.
Recommendations Update kedro-datasets to version 9.5.0. As a temporary mitigation, restrict the use of the kedro datasets experimental.pytorch.PyTorchDataset component or ensure only trusted files are loaded.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62997
GHSA-F9Q4-H45W-JRRQ

Affected Products

Pytorch
Kedro-Datasets