Skip to content

Pandas DataFrame.query Code Injection (Unpatched) #61559

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
clyormz opened this issue Jun 4, 2025 · 2 comments
Closed

Pandas DataFrame.query Code Injection (Unpatched) #61559

clyormz opened this issue Jun 4, 2025 · 2 comments
Labels
Closing Candidate May be closeable, needs more eyeballs expressions pd.eval, query

Comments

@clyormz
Copy link

clyormz commented Jun 4, 2025

Python pandas version 2.2.3 has a vulnerability on Pandas DataFrame.query

In order to fix the function query on DataFrame python class what are the elements to review to resolve the vulnerability CVE-2024-9880.

Regards

@asishm asishm added CI Continuous Integration Closing Candidate May be closeable, needs more eyeballs labels Jun 4, 2025
@asishm
Copy link
Contributor

asishm commented Jun 4, 2025

Hi, this CVE is rejected. Also discussed at #60602

@asishm asishm removed the CI Continuous Integration label Jun 4, 2025
@rhshadrach
Copy link
Member

Agreed @asishm, closing.

@rhshadrach rhshadrach added the expressions pd.eval, query label Jun 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Closing Candidate May be closeable, needs more eyeballs expressions pd.eval, query
Projects
None yet
Development

No branches or pull requests

3 participants