Description
Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On PyTorch versions earlier than 2.6, a malicious pickle-backed model from an attacker-influenced shared registry, downloaded checkpoint, or partitioned external source can execute arbitrary code when a Kedro pipeline loads it. The issue affects only the opt-in kedro_datasets_experimental component and does not affect users who load only trusted files. This issue is fixed in version 9.5.0.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Kedro-Datasets versions 5.0.0 through 9.4.x expose a remote code execution flaw when loading .pt model files with the experimental PyTorchDataset module. The module internally calls torch.load without enforcing the weights_only=True flag, and any user‑supplied load_args are ignored. On PyTorch releases older than 2.6, a malicious pickle-backed model can execute arbitrary code during the Kedro pipeline load process, allowing an attacker to run code within the service that processes the data. The vulnerability is limited to the opt‑in experimental component and does not affect users who load only trusted files.

Affected Systems

Products from kedro-org:kedro-plugins, specifically the kedro-datasets library, are affected between version 5.0.0 and the release that contains the fix (9.5.0). The issue manifests only when an infrastructure employs the experimental kedro_datasets_experimental.PyTorchDataset component to load external .pt files. Users who never enable or use this component, or who use only trusted file sources, are not impacted.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. The EPSS score is less than 1%, implying a low probability of exploitation at the time of analysis. The vulnerability is not included in the CISA KEV catalog. Exploitation would require a pipeline to load a maliciously crafted model file under PyTorch versions earlier than 2.6; the attacker must gain file access or influence the source of the .pt file. The fix is available in version 9.5.0, which disables the unsafe loading route.

Generated by OpenCVE AI on September 17, 2026 at 21:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade kedro-datasets to version 9.5.0 or later, where the unsafe torch.load usage is removed.
  • If an upgrade is not immediately possible, disable the experimental kedro_datasets_experimental.PyTorchDataset component or restrict its use strictly to fully trusted model files.
  • Ensure the runtime environment uses PyTorch version 2.6 or newer, as older releases are vulnerable to pickle execution via torch.load.

Generated by OpenCVE AI on September 17, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Kedro-org
Kedro-org kedro-plugins
Vendors & Products Kedro-org
Kedro-org kedro-plugins

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On PyTorch versions earlier than 2.6, a malicious pickle-backed model from an attacker-influenced shared registry, downloaded checkpoint, or partitioned external source can execute arbitrary code when a Kedro pipeline loads it. The issue affects only the opt-in kedro_datasets_experimental component and does not affect users who load only trusted files. This issue is fixed in version 9.5.0.
Title Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load`
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Kedro-org Kedro-plugins
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:55:22.149Z

Reserved: 2026-07-14T23:10:57.032Z

Link: CVE-2026-62997

cve-icon Vulnrichment

Updated: 2026-09-17T14:55:16.491Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:12.990

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-62997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data