PatchSiren

kedro-org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH kedro-org CVE published 2026-06-12

CVE-2026-3840

A high-severity path traversal vulnerability exists in Kedro version 1.2.0. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization, allowing an attacker to escape the intended versioned dataset directory and access files outside the expected path. This issue is also reachable through the CLI via the `--load-ve [truncated]

CRITICAL kedro-org CVE published 2026-04-06

CVE-2026-35171

CVE-2026-35171 is a critical remote code execution vulnerability in Kedro, a toolbox for production-ready data science. The vulnerability is caused by unsafe use of logging.config.dictConfig() with user-controlled input. An attacker can exploit this to execute arbitrary system commands during application startup. This vulnerability affects Kedro versions prior to 1.3.0 and has a CVSS score of 9.8, indicat [truncated]