Executive brief
Aeon is a time-series analysis toolkit used by data scientists and researchers for machine learning workflows. A deserialization vulnerability in the load_rehab_pile_dataset method allows attackers to execute arbitrary code on a user's machine when they open a malicious file or visit a specially crafted page, potentially compromising research data, system integrity, or enabling further network penetration.
Technical details
The vulnerability is a deserialization-of-untrusted-data flaw in Aeon's load_rehab_pile_dataset method, resulting from insufficient validation of user-supplied input. The attack vector is local with user interaction required—an attacker must trick a user into opening a malicious file or visiting a malicious page. The attack results in arbitrary code execution in the context of the current process. A patch is available via GitHub commit 751918052c0cce266b4f7cd4b084408526efc015.
Affected products
- Aeon Aeon
Timeline
- 2026-02-17: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release of advisory
- 2026-07-29: patched: Update issued; patch available at GitHub commit 751918052c0cce266b4f7cd4b084408526efc015