Loading HuntDB...

GHSA-6hrg-qmvc-2xh8

GitHub Security Advisory

joblib vulnerable to arbitrary code execution

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

The package joblib from 0 and before 1.2.0 is vulnerable to Arbitrary Code Execution via the `pre_dispatch` flag in `Parallel()` class due to the `eval()` statement.

Affected Packages

PyPI joblib
Affected versions: 0 (fixed in 1.2.0)

Related CVEs

Key Information

GHSA ID
GHSA-6hrg-qmvc-2xh8
Published
September 27, 2022 12:00 AM
Last Modified
September 23, 2024 7:29 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
joblib
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.