catalyst@20.12 vulnerabilities

Catalyst. Accelerated deep learning R&D with PyTorch.

Direct Vulnerabilities

Known vulnerabilities in the catalyst package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Deserialization of Untrusted Data

catalyst is a Catalyst. PyTorch framework for DL research and development.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data. The load() function from the yaml package is used to deserialize untrusted input.

How to fix Deserialization of Untrusted Data?

Upgrade catalyst to version 21.1rc0 or higher.

[,21.1rc0)