Vulnerability: Arbitrary Code Execution via Pickle Deserialization in joblib.load()
Target Format: .joblib (High-Value Target, up to $1,500)
joblib.load() uses Python's pickle module internally without any integrity verification. An attacker can craft a malicious .joblib file containing a
reduce payload that executes arbitrary code during deserialization.
This affects ALL versions of joblib and any application that calls… See the full description on the dataset page:
https://huggingface.co/datasets/tfa0/joblib-ace-poc.