Refuel maintains a focused product line centered on its autolabel offering, which provides data annotation and labeling automation for machine-learning pipelines. The observed vulnerabilities cluster around code-execution risks inherent to dynamically evaluated expressions and formula injection in data formats, reflecting the product's exposure to untrusted input processing and data handling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Refuel over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27321HIGH An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided | Sep 12, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-27320HIGH An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. | Sep 12, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Refuel.
Media articles that mention a CVE ID that affects a product developed by Refuel — matched by CVE ID, not by vendor name.