Impact
Kedro-Datasets versions 5.0.0 through 9.4.x expose a remote code execution flaw when loading .pt model files with the experimental PyTorchDataset module. The module internally calls torch.load without enforcing the weights_only=True flag, and any user‑supplied load_args are ignored. On PyTorch releases older than 2.6, a malicious pickle-backed model can execute arbitrary code during the Kedro pipeline load process, allowing an attacker to run code within the service that processes the data. The vulnerability is limited to the opt‑in experimental component and does not affect users who load only trusted files.
Affected Systems
Products from kedro-org:kedro-plugins, specifically the kedro-datasets library, are affected between version 5.0.0 and the release that contains the fix (9.5.0). The issue manifests only when an infrastructure employs the experimental kedro_datasets_experimental.PyTorchDataset component to load external .pt files. Users who never enable or use this component, or who use only trusted file sources, are not impacted.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score is less than 1%, implying a low probability of exploitation at the time of analysis. The vulnerability is not included in the CISA KEV catalog. Exploitation would require a pipeline to load a maliciously crafted model file under PyTorch versions earlier than 2.6; the attacker must gain file access or influence the source of the .pt file. The fix is available in version 9.5.0, which disables the unsafe loading route.
OpenCVE Enrichment