ECHO-e3b7-5995-8269

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-e3b7-5995-8269.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-e3b7-5995-8269
Upstream
Withdrawn
2025-10-16T11:45:06Z
Published
2026-01-29T00:50:47Z
Modified
2026-09-15T03:33:36Z
Summary
third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner. https://nvd.nist.gov/vuln/detail/CVE-2020-13092
Details
References

Affected packages

Echo / scikit-learn

Package

Name
scikit-learn
Purl
pkg:deb/echo/scikit-learn

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.2+dfsg-8+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-e3b7-5995-8269.json"