CVE-2026-35171 | kedro-org kedro up to 1.2.x dictConfig KEDRO_LOGGING_CONFIG code injection (GHSA-9cqf-439c-j96r)
A vulnerability was found in kedro-org kedro up to 1.2.x. It has been declared as critical. Affected by this issue is the function dictConfig. The manipulation of the argument KEDRO_LOGGING_CONFIG results in code injection.
This vulnerability is known as CVE-2026-35171. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.