Database/AI/ML frameworks & serving
joblib: Arbitrary code execution via `eval` on the `pre_dispatch` flag in `Parallel()`
CVSS 7.3CVE-2022-21797AI/ML frameworks & servingcurated
Impact
Arbitrary code execution via eval on the pre_dispatch flag in Parallel()
Who can reach it
Tenant code passing attacker-influenced strings
What to do
Upgrade joblib >= 1.2.0 in base images
References
Related entries
- Gradio: Lack of path filteringCVE-2023-34239 · GradioHigh
- jupyter-lsp: Unauthenticated file read/write through the LSP extensionCVE-2024-22415 · jupyter-lspHigh
- SGLang (`/update_weights_from_tensor`): Unsafe deserialization of the `serialized_named_tensors` argumentCVE-2025-10164 · SGLang (`/update_weights_from_tensor`)High
- Jupyter Core (Windows): Config read from a shared writable pathCVE-2025-30167 · Jupyter Core (Windows)High
- llama-index-core: Predictable hardcoded cache directoryCVE-2025-7647 · llama-index-coreHigh
- Keras (HDF5 path): Code execution from crafted `.h5`/`.hdf5` model despite safe modeCVE-2025-9905 · Keras (HDF5 path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.