CVE-2026-35167 | kedro-org kedro up to 1.2.x kedro/io/core.py _get_versioned_path path traversal (GHSA-6326-w46w-ppjw)
A vulnerability described as critical has been identified in kedro-org kedro up to 1.2.x. The impacted element is the function _get_versioned_path of the file kedro/io/core.py. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-35167. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.