CVE-2021-24040

CRITICAL

Facebook Parlai < 1.1.0 - Insecure Deserialization

Title source: rule

Description

Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

Exploits (1)

exploitdb WORKING POC
by Abhiram V · pythonlocalpython
https://www.exploit-db.com/exploits/50289

Scores

CVSS v3 9.8
EPSS 0.3624
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

facebook/parlai < 1.1.0
pypi/parlai < 1.1.0PyPI

Timeline

Published Sep 10, 2021
Tracked Since Feb 18, 2026