PT-2026-94089 · Meta+1 · Pytorch+1
CVE-2026-62997
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
kedro-datasets versions 5.0.0 through 9.4.9
Description
The
kedro datasets experimental.pytorch.PyTorchDataset component loads .pt model files using the torch.load function without enforcing the weights only=True parameter, and it silently drops user-supplied load args. When used with PyTorch versions earlier than 2.6, this allows a malicious pickle-backed model—sourced from a compromised shared registry, downloaded checkpoint, or external source—to execute arbitrary code during the loading process in a Kedro pipeline. This issue specifically affects the opt-in kedro datasets experimental component.Recommendations
Update kedro-datasets to version 9.5.0.
As a temporary mitigation, restrict the use of the
kedro datasets experimental.pytorch.PyTorchDataset component or ensure only trusted files are loaded.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pytorch
Kedro-Datasets