A high-severity path traversal vulnerability exists in Kedro version 1.2.0. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization, allowing an attacker to escape the intended versioned dataset directory and access files outside the expected path. This issue is also reachable through the CLI via the `--load-ve [truncated]
CVE-2026-35171 is a critical remote code execution vulnerability in Kedro, a toolbox for production-ready data science. The vulnerability is caused by unsafe use of logging.config.dictConfig() with user-controlled input. An attacker can exploit this to execute arbitrary system commands during application startup. This vulnerability affects Kedro versions prior to 1.3.0 and has a CVSS score of 9.8, indicat [truncated]