kedro-datasets
First-party plugins maintained by the Kedro team.
Activity
- Latest release
- 1mo ago
- Total releases
- 45
- Cadence
- ~31 days
- Last 12 months
- 8
Reach
- Stars
- 119
Details
- License
- unknown
- First release
- Jun 22, 2022
| Version | Released | |
|---|---|---|
9.6.0
minor
| ||
9.5.0
minor
| ||
9.4.0
minor
| ||
9.3.0
minor
| ||
9.2.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
8.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
8.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
6.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
5.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
5.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.3
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.2
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.7
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.6
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.5
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.4
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.3
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.2
patch
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2026-35492
PYSEC-2026-2545
GHSA-cjg8-h5qc-hrjv
Jul 13, 2026
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactPartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured dataset directory, potentially overwriting arbitrary files on the filesystem. Users of PartitionedDataset with any storage backend (local filesystem, S3, GCS, etc.) are affected. PatchesYes. The vulnerability has been patched in kedro-datasets version 9.3.0.
Users should upgrade to kedro-datasets >= 9.3.0. The fix normalizes constructed paths using WorkaroundsUsers who cannot upgrade should validate partition IDs before passing them to PartitionedDataset, ensuring they do not contain ReferencesFix: https://github.com/kedro-org/kedro-plugins/pull/1346 Report: https://github.com/kedro-org/kedro/issues/5452 Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
+ 29 more Show less
1.2.0
1.3.0
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
3.0.0
3.0.1
4.0.0
4.1.0
5.0.0
5.1.0
6.0.0
7.0.0
8.0.0
8.1.0
9.0.0
9.1.0
9.1.1
9.2.0
Fixed in
9.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev |