Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

scio is vunerable to Remote Command Execution through PyTorch

GHSA-m9mp-6x32-5rhg

Published ยท Modified

Description

Impact

PyTorch reported a critical vulnerability when using torch.load, even with option weights_only=True, for torch <= 2.5.1.

In scio <= 1.0.0, the lower bound for torch is 2.3.

Patches

The lower bound was changed to torch >= 2.6, starting from scio >= 1.0.1 (currently in dev state).

Workarounds

You can manually check that you are using torch >= 2.6.

Ready to move

Start Securing

Free, no credit card | First findings in minutes