{"data":{"ecosystem":"pypi","name":"scikit-learn","url":"https://aisecwatch.com/packages/pypi/scikit-learn","latestVersion":"1.9.1","firstReleaseAt":"2011-09-22T00:03:10.112Z","repository":"https://github.com/scikit-learn/scikit-learn","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"joblib","versionSpec":">=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"narwhals","versionSpec":">=2.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.24.1","scope":"runtime"},{"ecosystem":"pypi","name":"scipy","versionSpec":">=1.10.0","scope":"runtime"},{"ecosystem":"pypi","name":"threadpoolctl","versionSpec":">=3.5.0","scope":"runtime"}],"advisories":[{"id":"24b9f939-b723-41de-a55c-aa7e907da1e3","url":"https://aisecwatch.com/issues/24b9f939-b723-41de-a55c-aa7e907da1e3","cveId":"CVE-2024-5206","title":"CVE-2024-5206: A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to…","headline":"scikit-learn TfidfVectorizer leaks sensitive training tokens via stop_words_","severity":"medium","publishedAt":"2024-06-06T23:16:06.363Z","affected":["scikit-learn@< 1.5.0 (fixed: 1.5.0)"],"epssScore":0.00189},{"id":"ba619926-87b4-402c-a4cc-e4e1fa5bb8a1","url":"https://aisecwatch.com/issues/ba619926-87b4-402c-a4cc-e4e1fa5bb8a1","cveId":"CVE-2020-28975","title":"CVE-2020-28975: svm_predict_values in svm.cpp in Libsvm v324, as used in scikit-learn 0.23.2 and other products, allows attackers to…","headline":"Libsvm svm_predict_values denial of service via crafted SVM model","severity":"high","publishedAt":"2020-11-22T02:15:10.680Z","affected":["scikit-learn@>= 0.23.2, < 1.0.1 (fixed: 1.0.1)"],"epssScore":0.035},{"id":"a9292361-2294-45a9-8135-058ba0582b78","url":"https://aisecwatch.com/issues/a9292361-2294-45a9-8135-058ba0582b78","cveId":"CVE-2020-13092","title":"CVE-2020-13092: scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to…","headline":"scikit-learn unsafe deserialization via joblib.load of untrusted file","severity":"critical","publishedAt":"2020-05-15T23:15:12.277Z","affected":["scikit-learn@<= 0.23.0"],"epssScore":0.03363}],"checkedAt":"2026-10-09T21:49:42.281Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}