Executive brief
Aeon is a Python toolkit for time series analysis and machine learning. A code injection vulnerability in the load_time_series_segmentation_benchmark method allows attackers to execute arbitrary Python code if a user opens a malicious file or visits a malicious webpage. An attacker could gain full control over the user's system and access sensitive data.
Technical details
The vulnerability exists in the load_time_series_segmentation_benchmark method due to insufficient validation of user-supplied input before it is passed to Python code execution. The flaw is a code injection vulnerability that allows an attacker to inject arbitrary Python code. Exploitation requires user interaction—the target must open a malicious file or visit a malicious web page. The attack vector is local with user interaction required. An attacker can execute code in the context of the current process, potentially leading to full system compromise. A patch has been released by the vendor (commit 7519180).
Affected products
- Aeon Aeon
Timeline
- 2026-02-19: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public release of advisory (ZDI-26-470)
- 2026-07-29: patched: Patch released via GitHub commit 7519180