GHSA-m9mp-6x32-5rhg: scio is vunerable to Remote Command Execution through PyTorch
PyTorch reported a critical vulnerability when using torch.load, even with option weights_only=True, for torch <= 2.5.1.
In scio <= 1.0.0, the lower bound for torch is 2.3.
References
Code Behaviors & Features
Detect and mitigate GHSA-m9mp-6x32-5rhg with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →