CVE-2024-27322: R Project R

High severity, CVSS 8.8. EPSS: 23.4% chance of exploitation in the next 30 days.

Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.

Affected products

  • R Project R: from 1.4.0, before 4.4.0 (fixed in 4.4.0)
  • The R Project R: from 1.4.0, before 4.4.0 (fixed in 4.4.0)

Published 2024-04-29. Last modified 2026-06-17.