CVE-2024-45857: Cleanlab
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.
Affected products
- Cleanlab Cleanlab: from 2.4.0; from 2.4
Published 2024-09-12. Last modified 2026-06-17.