CVE-2024-45857: Cleanlab

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the data directory is loaded.

Affected products

Published 2024-09-12. Last modified 2026-06-17.