{"id":"ECHO-e3b7-5995-8269","summary":"third parties dispute this issue because the joblib.load() function is\ndocumented as unsafe and it is the user's responsibility to use the\nfunction in a secure manner.\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-13092","modified":"2026-09-15T03:33:36.314248326Z","published":"2026-01-29T00:50:47.605569Z","withdrawn":"2025-10-16T11:45:06.677Z","upstream":["CVE-2020-13092"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2020-13092"}],"affected":[{"package":{"name":"scikit-learn","ecosystem":"Echo","purl":"pkg:deb/echo/scikit-learn"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.2+dfsg-8+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-e3b7-5995-8269.json"}}],"schema_version":"1.9.0"}