CVE-2026-3840 | kedro-org kedro up to up to 1.2.0 kedro/io/core.py _get_versioned_path –load-versions path traversal

SecurityVulns

A vulnerability identified as critical has been detected in kedro-org kedro up to up to 1.2.0. Affected by this vulnerability is the function _get_versioned_path of the file kedro/io/core.py. This manipulation of the argument –load-versions causes path traversal.

This vulnerability is registered as CVE-2026-3840. The attack needs to be launched locally. No exploit is available.VulDB Recent EntriesRead More