VYPR
Critical severity9.8OSV Advisory· Published Jan 16, 2019· Updated Jun 17, 2026

CVE-2019-6446

CVE-2019-6446

Description

An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
numpyPyPI
< 1.16.31.16.3

Affected products

58

Patches

Vulnerability mechanics

References

19

News mentions

0

No linked articles in our index yet.