By vendor
Linuxfoundation vulnerabilities
Known CVEs affecting Linuxfoundation products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-3840HIGH 7.1
A path traversal vulnerability in Kedro 1.2.0 allows an authenticated local attacker to break out of the intended dataset directory structure by injecting specially crafted version strings. The flaw exists in how the data pipeline tool constructs file paths when versioning datasets, enabling unauthorized access to files outside the expected scope. This can be exploited both programmatically and via the command-line interface, potentially allowing attackers to read sensitive files or inject malicious data into shared environments.