peter bassill · operator
$ cve CVE-2021-24040 JSON

CVE-2021-24040 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 17.4% (pctl 97)

Patch early

A public exploit exists.

Description

Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.35% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2021-09-10
Last modified2026-06-17

Affected (1)

VendorProduct
facebookparlai

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD