VYPR

Kedro

by Pypi

CVEs (1)

  • CVE-2026-3840HigJun 12, 2026
    risk 0.46cvss 7.1epss

    A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization.…