Vulnerability CVE-2024-45857


Published: 2024-09-12

Description:
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user??s system when the data directory is loaded.

 References:
https://hiddenlayer.com/sai-security-advisory/2024-09-cleanlab/

Copyright 2026, cxsecurity.com

 

Back to Top