{"id":"GHSA-ghq9-vc6f-8qjf","summary":"TorchGeo Remote Code Execution Vulnerability","details":"### Impact\n\nTorchGeo 0.4–0.6.0 used an [`eval`](https://docs.python.org/3/library/functions.html#eval) statement in its model weight API that could allow an unauthenticated, remote attacker to execute arbitrary commands. All platforms that expose [`torchgeo.models.get_weight()`](https://torchgeo.readthedocs.io/en/v0.6.0/api/models.html#torchgeo.models.get_weight) or [`torchgeo.trainers`](https://torchgeo.readthedocs.io/en/v0.6.0/api/trainers.html) as an external API could be affected.\n\n### Patches\n\nThe `eval` statement was replaced with a fixed enum lookup, preventing arbitrary code injection. All users are encouraged to upgrade to TorchGeo 0.6.1 or newer.\n\n### Workarounds\n\nIn unpatched versions, input validation and sanitization can be used to avoid this vulnerability.\n\n### References\n\n#### Bug history\n\n* Introduced: https://github.com/torchgeo/torchgeo/pull/917\n* Patched: https://github.com/torchgeo/torchgeo/pull/2323\n* Released: [v0.6.1](https://github.com/microsoft/torchgeo/releases/tag/v0.6.1)","aliases":["CVE-2024-49048","PYSEC-2024-204"],"modified":"2026-04-01T00:26:15.674531Z","published":"2026-04-01T00:03:56Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94","CWE-95"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-01T00:03:56Z"},"references":[{"type":"WEB","url":"https://github.com/torchgeo/torchgeo/security/advisories/GHSA-ghq9-vc6f-8qjf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49048"},{"type":"WEB","url":"https://github.com/torchgeo/torchgeo/pull/2323"},{"type":"WEB","url":"https://github.com/torchgeo/torchgeo/pull/917"},{"type":"WEB","url":"https://github.com/torchgeo/torchgeo/commit/1a980788cb7089a1115f3b786c7daa9dd47d7d7a"},{"type":"WEB","url":"https://github.com/microsoft/torchgeo/releases/tag/v0.6.1"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/torchgeo/PYSEC-2024-204.yaml"},{"type":"PACKAGE","url":"https://github.com/torchgeo/torchgeo"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49048"}],"affected":[{"package":{"name":"torchgeo","ecosystem":"PyPI","purl":"pkg:pypi/torchgeo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.4"},{"fixed":"0.6.1"}]}],"versions":["0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.6.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-ghq9-vc6f-8qjf/GHSA-ghq9-vc6f-8qjf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}