pypi package report

Is torchgeo safe?

1 known vulnerability, worst severity HIGH.

cvss
8.1

how bad it is if exploited, out of 10

epss
1.2%

chance of exploitation in the next 30 days

xyz score
3.9

CyberXYZ composite, out of 10

fig. 01 — GHSA-ghq9-vc6f-8qjf, the advisory selected below

// advisories

GHSA-ghq9-vc6f-8qjf

HIGHCVE-2024-49048

TorchGeo 0.4–0.6.0 used an [eval](https://docs.python.org/3/library/functions.html#eval) statement in its model weight API that could allow an unauthenticated, remote attacker to execute arbitrary commands. All platforms that expose [torchgeo.models.getweight()](https://torchgeo.readthedocs.io/en/v0.6.0/api/models.html#torchgeo.models.getweight) or [torchgeo.trainers](https://torchgeo.readthedocs.

Affected
>= 0.4, <= 0.6.0
Fixed in
0.6.1
Weakness
CWE-94
Published
2026-04-01
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereference


// dependencies

45 direct, 10 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

1 published models

0 declared · 1 observed · 0 inferred

ModelEvidence
ByteDance/LatentSync-1.6observed

1 published AI models are associated with this package: 0 name it in a requirements or pyproject file, 1 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 0 state a version requirement, so this is not a count of affected models.


Checked 2026-09-22 at 00:46 UTC. The most recent advisory here was published 2026-04-01. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is torchgeo safe? pypi package security report | CyberXYZ