In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-20 | 
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-94 | 
Thu, 20 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine. | |
| Title | Remote Code Execution in kedro-org/kedro | |
| Weaknesses | CWE-20 | |
| References |  | |
| Metrics | cvssV3_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:39.404Z
Updated: 2025-10-15T12:49:30.535Z
Reserved: 2024-12-04T21:51:30.505Z
Link: CVE-2024-12215
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-20T17:34:58.060Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-03-20T10:15:27.333
Modified: 2025-10-15T13:15:39.640
Link: CVE-2024-12215
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow