VYPR
High severity7.8NVD Advisory· Published Sep 12, 2024· Updated Apr 15, 2026

CVE-2024-45857

CVE-2024-45857

Description

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cleanlabPyPI
>= 2.4.0, <= 2.6.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.