Impact
This vulnerability allows attackers to deserialize data from arbitrary sources via the from_npy_stack function in the Loader module of Dask. The resulting deserialization could enable execution of arbitrary code on the host if untrusted input is processed.
Affected Systems
All releases of the Dask library up to and including version 2026.8.0 contain the flaw. The affected component is the Loader implementation within dask/array/core.py. The issue is purely software‑level and can appear in any environment that deploys the impacted Dask code.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, and a publicly disclosed exploit exists, which increases the likelihood compared to an unknown theoretical flaw. The lack of a vendor patch at the time of report means the risk remains until a fix or mitigative measure is applied.
OpenCVE Enrichment