CVE-2020-13091: Numfocus Pandas

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

Affected products

  • Numfocus Pandas: up to and including 1.0.3

Published 2020-05-15. Last modified 2026-06-17.