GHSA-ghq9-vc6f-8qjf
HIGHCVE-2024-49048TorchGeo 0.4–0.6.0 used an [eval](https://docs.python.org/3/library/functions.html#eval) statement in its model weight API that could allow an unauthenticated, remote attacker to execute arbitrary commands. All platforms that expose [torchgeo.models.getweight()](https://torchgeo.readthedocs.io/en/v0.6.0/api/models.html#torchgeo.models.getweight) or [torchgeo.trainers](https://torchgeo.readthedocs.
- Affected
- >= 0.4, <= 0.6.0
- Fixed in
- 0.6.1
- Weakness
- CWE-94
- Published
- 2026-04-01
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference