
Critical RCE fixed in Kedro logging configuration
CVE-2026-35171 discloses a Critical RCE in `kedro` <1.3.0 where an attacker-influenced `KEDRO_LOGGING_CONFIG` path can trigger unsafe `logging.config.dictConfig()` execution at startup.
NewsPythonSecure Configuration
1 minYesterday
