CVE-2019-6446Critical· 9.8▾ AbyssalPoC availableNumpy Deserialization of Untrusted Data
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 2.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
17%
17% → 18%
1 GitHub repo
** DISPUTED ** An issue was discovered in NumPy 1.16.2 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.
numpy < 1.16.3Upgrade to a patched release:
numpy 1.16.3Field changes observed since this record was first indexed.