deeplake@3.2.8 vulnerabilities

Data Lake for Multi-Modal AI Search

Direct Vulnerabilities

Known vulnerabilities in the deeplake package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Improper Command Injection

deeplake is an Activeloop Deep Lake

Affected versions of this package are vulnerable to Improper Command Injection due to a lack of input sanitization in the ingest_kaggle API. An attacker can execute arbitrary commands by sending specially crafted inputs to the API.

How to fix Improper Command Injection?

Upgrade deeplake to version 3.9.11 or higher.

[,3.9.11)