← Back to browse · API

CVE-2024-27322

Severity
HIGH
CVSS
8.8
EPSS
0.23618
Risk score
43.47
CISA KEV
No
PoC
No
Published
2024-04-29
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-24532, GHSA-82X4-8Q4X-2QXV
Products
R-Project:R 1.4.0 <4.4.0
Sources
euvd EUVD-2024-24532

Description

Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.

References