Scikit-learn is a Python machine-learning library with a narrow product scope that has become foundational to data science and ML workflows across industry and research. The vendor's disclosed vulnerabilities have centered on the core library itself, though the durable weakness landscape for this library class remains sparse. Current exposure counts and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scikit Learn over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13092CRITICAL scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system | May 15, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-28975HIGH svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to cause a denial of service (segmentation fault) via a crafted mo | Nov 21, 2020 | 7.5 | 21 | NO | NO |
CVE-2024-5206MEDIUM A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. | Jun 6, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scikit Learn.
Media articles that mention a CVE ID that affects a product developed by Scikit Learn — matched by CVE ID, not by vendor name.