Executive brief
Snorkel is a Python library used by data scientists to programmatically build and manage training datasets for machine learning. A security flaw in how the library loads saved models allows a malicious actor to execute unauthorized code on a user's computer. This occurs if a user is tricked into loading a specially crafted model file, potentially leading to a full system compromise or data theft.
Technical details
The Snorkel library (up to and including v0.10.0) contains an insecure deserialization vulnerability (CWE-502) within the BaseLabeler.load() method. The root cause is the use of the unsafe Python 'pickle.load()' function to process serialized labeler models from user-provided file paths without validation. Because the pickle module can instantiate arbitrary Python objects, a remote attacker can craft a malicious pickle file that executes arbitrary commands when deserialized. Exploitation requires the victim to load the malicious file, resulting in full code execution in the context of the application. As of the advisory date, no patched version has been identified.
Affected products
- snorkel-team snorkel <= 0.10.0
Timeline
- 2026-05-12: advisory: NVD and GitHub Advisory published
- 2026-05-18: other: GitHub Advisory reviewed and updated