Home » Database

AVID-2026-R1497

Description

Vulnerability CVE-2024-37062

Details

Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata’s ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code on an end user’s system when loaded.

Reason for inclusion in AVID: The report describes CVE-2024-37062, a deserialization vulnerability in Ydata’s ydata-profiling library (>=3.7.0) that enables arbitrary code execution when loading a crafted report. This is a software vulnerability in a component commonly used in ML/AI data processing pipelines, and such libraries are often dependencies in AI workflows. Therefore it is a relevant supply-chain risk for general-purpose AI systems.

References

Affected or Relevant Artifacts

  • Developer: YdataAI
  • Deployer: YdataAI
  • Artifact Details:
TypeName
Systemydata-profiling

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score7.8
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-502CWE-502 Deserialization of Untrusted Data

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-06-04
  • Version: 0.3.3
  • AVID Entry