id: PYSEC-2026-2438 published: "2026-07-13T14:36:37.559737Z" modified: "2026-07-13T16:03:50.297431Z" aliases: - CVE-2026-2970 - GHSA-hg58-x52p-859c summary: datapizza-ai has unsafe deserialization via pickle.loads() in RedisCache details: A vulnerability has been found in datapizza-labs datapizza-ai 0.0.7. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization. The attack requires being on the local network. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. affected: - package: name: datapizza-ai-core ecosystem: PyPI purl: pkg:pypi/datapizza-ai-core ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 0.0.7 versions: - 0.0.1 - 0.0.2 - 0.0.3 - 0.0.4 - 0.0.5 - 0.0.6 - 0.0.7 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-2970 - type: PACKAGE url: https://github.com/datapizza-labs/datapizza-ai - type: WEB url: https://github.com/hacktivesec/datapizza-ai-disclosure/blob/main/unsafe-deserialization.md - type: WEB url: https://vuldb.com/?ctiid.347337 - type: WEB url: https://vuldb.com/?id.347337 - type: WEB url: https://vuldb.com/?submit.755363 - type: PACKAGE url: https://pypi.org/project/datapizza-ai-core - type: ADVISORY url: https://github.com/advisories/GHSA-hg58-x52p-859c severity: - type: CVSS_V3 score: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L - type: CVSS_V4 score: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P