| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cjg8-h5qc-hrjv | kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kedro-org
Kedro-org kedro-plugins |
|
| Vendors & Products |
Kedro-org
Kedro-org kedro-plugins |
Wed, 08 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. This vulnerability is fixed in 9.3.0. | |
| Title | Kedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file write | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T14:50:03.601Z
Reserved: 2026-04-02T20:49:44.454Z
Link: CVE-2026-35492
Updated: 2026-04-08T14:49:56.021Z
Status : Awaiting Analysis
Published: 2026-04-07T16:16:27.620
Modified: 2026-04-08T21:27:00.663
Link: CVE-2026-35492
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:48:31Z
Github GHSA