kedro vulnerabilities
CVEs whose affected-version data names the kedro package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-12215High· 8.8Kedro allows Remote Code Execution by Pulling Micro Packages
Kedro allows Remote Code Execution by Pulling Micro Packages
▾ Twilightkedro · kedroEPSS 1.1%via OSV
CVE-2024-9701Critical· 9.8Kedro deserialization vulnerability
Kedro deserialization vulnerability
▾ Midnightkedro · kedroEPSS 1.1%via OSV