CVE-2021-24040 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 17.4% (pctl 97)
Patch early
A public exploit exists.
Description
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 17.35% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-09-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| parlai |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Facebook ParlAI 1.0.0 - Deserialization of Untrusted Data in parlai | 2021-09-13 |
References
- http://packetstormsecurity.com/files/164136/Facebook-ParlAI-1.0.0-Code-Execution-Deserialization.html
- https://github.com/facebookresearch/ParlAI/releases/tag/v1.1.0
- https://github.com/facebookresearch/ParlAI/security/advisories/GHSA-m87f-9fvv-2mgg
- http://packetstormsecurity.com/files/164136/Facebook-ParlAI-1.0.0-Code-Execution-Deserialization.html
- https://github.com/facebookresearch/ParlAI/releases/tag/v1.1.0
- https://github.com/facebookresearch/ParlAI/security/advisories/GHSA-m87f-9fvv-2mgg
→ the Explorer · watch your stack · NVD