| Summary | Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded. |
|---|---|
| Publication Date | Sept. 12, 2024, 10:15 p.m. |
| Registration Date | Sept. 13, 2024, 5 a.m. |
| Last Update | Sept. 12, 2024, 10:15 p.m. |