PT-2024-8093 · Torchgeo · Torchgeo

Zpbrent

·

Published

2024-11-12

·

Updated

2026-04-01

·

CVE-2024-49048

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TorchGeo (affected versions not specified)
Description: The issue is related to incorrect code generation management in the TorchGeo library, which handles geospatial data. This can allow a remote attacker to execute arbitrary code.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

BDU:2024-09614
CVE-2024-49048
GHSA-G5VP-J278-8PJH
GHSA-GHQ9-VC6F-8QJF
PYSEC-2024-204

Affected Products

Torchgeo