NumFocus is an open-source scientific-computing umbrella organization whose vulnerability exposure centers on the pandas data manipulation library, a foundational component in Python-based data analysis and machine-learning workflows. The observed weakness class—deserialization of untrusted data—reflects the parsing complexity inherent to a library that ingests external data formats. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Numfocus over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13091CRITICAL pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third pa | May 15, 2020 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Numfocus.
Media articles that mention a CVE ID that affects a product developed by Numfocus — matched by CVE ID, not by vendor name.