Skip to content

fix: upgrade vulnerable dependencies in TORR benchmark requirements - #1979

Open
yoavkatz wants to merge 1 commit into
mainfrom
fix/torr-security-deps-1978
Open

yoavkatz wants to merge 1 commit into
mainfrom
fix/torr-security-deps-1978

Conversation

@yoavkatz

Copy link
Copy Markdown
Member

Resolves the Dependabot alerts tracked in #1978.

Where the alerts come from

The repo has only two dependency manifests (no lockfiles, no setup.py, no conda envs) and no .github/dependabot.yml, so Dependabot auto-discovers both:

  1. pyproject.toml
  2. prepare/benchmarks/torr/requirements.txt

All three alerted packages trace to prepare/benchmarks/torr/requirements.txt — the only manifest that still pinned them below the patched releases. The pyproject.toml occurrences are not the source: the tests extra pins scikit-learn<=1.5.2, a range that already excludes the vulnerable <1.5.0, and the remaining entries are unpinned.

Note these alerts were previously resolved and then re-added. #1968 bumped torch, transformers, nltk, protobuf, requests, gradio and bs4 in this same file but left scikit-learn, py7zr and accelerate untouched — exactly the three packages flagged now.

Changes

Package Before After CVEs
scikit-learn ==1.2.0 >=1.5.0 CVE-2024-5206 (medium) — sensitive data leakage in TfidfVectorizer.stop_words_
py7zr ==0.20.6 >=1.1.3 CVE-2026-23879 (high) arbitrary file write; CVE-2026-55195 (medium) decompression bomb DoS; CVE-2026-55206 (medium) quadratic complexity DoS in PackInfo._read()
accelerate ==0.34.2 >=1.15.0 CVE-2026-69112 (medium)

Lower bounds are used instead of exact pins so future security patches are picked up without another manual bump, consistent with the style adopted for torch/transformers/protobuf in #1968.

Verification

  • Resolved the complete requirements set with uv pip compile --python-version 3.10: resolves cleanly with no conflicts, yielding scikit-learn 1.7.2, py7zr 1.1.3, accelerate 1.15.0. Both new floors require Python >= 3.10, which the ToRR flow satisfies.
  • No repo code changed. This file is referenced only from prepare/benchmarks/torr/README.md for manual benchmark runs and is not installed by CI.
  • Pre-commit hooks pass.

Two caveats for reviewers

CVE-2026-69112 (accelerate) has no upstream fix. The advisory lists no patched version. OSV's "fixed" event points at commit beb0672, which is only the v1.14.0 release bump — it marks the last-affected boundary rather than a fix. Diffing the 1.14.0 and 1.15.0 sdists confirms the vulnerable os.path.join(checkpoint_folder, f) in utils/modeling.py, which joins unvalidated paths taken from the index JSON, is unchanged. So 1.15.0 is the latest release but still technically affected, and Dependabot may continue to flag it. Mitigating factor: unitxt never calls load_checkpoint_and_dispatch directly, reaching accelerate only through transformers' device_map, so the path is not reachable with attacker-controlled checkpoints via unitxt's own API. Bumping moves the pin off the flagged 0.34.2 and will pick up the real fix once released.

pyproject.toml scikit-learn<=1.5.2 left unchanged. It is not vulnerable, and the upper bound appears deliberate — it mirrors the scikit-learn==1.5.2 pin in .github/workflows/test_helm.yml, which runs on Python 3.9 for HELM compatibility. Widening it risks breaking that job for no security benefit, so it seemed better handled separately if desired.

🤖 Generated with Claude Code

Remediates the Dependabot alerts tracked in #1978. All three alerted
packages were pinned to vulnerable versions in the ToRR benchmark
requirements file, the only manifest in the repo that still pinned them
below the patched releases:

- scikit-learn 1.2.0 -> >=1.5.0 (CVE-2024-5206, medium)
  Sensitive data leakage in TfidfVectorizer.stop_words_
- py7zr 0.20.6 -> >=1.1.3 (CVE-2026-23879 high, CVE-2026-55195,
  CVE-2026-55206 medium) arbitrary file write, decompression bomb DoS,
  and quadratic complexity DoS in PackInfo._read()
- accelerate 0.34.2 -> >=1.15.0 (CVE-2026-69112, medium)

CVE-2026-69112 has no patched release upstream; 1.15.0 is the latest
available, and unitxt does not call the affected
load_checkpoint_and_dispatch path directly, reaching accelerate only
via transformers device_map. Bumping keeps the pin off the flagged
0.34.2 and picks the fix up automatically once released.

Lower bounds are used instead of exact pins so future security patches
are picked up without another manual bump, consistent with the style
adopted for torch/transformers/protobuf in #1968.

Verified the full requirements set still resolves with
`uv pip compile --python-version 3.10`, yielding scikit-learn 1.7.2,
py7zr 1.1.3 and accelerate 1.15.0 with no conflicts.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Yoav Katz <katz@il.ibm.com>
@yoavkatz
yoavkatz enabled auto-merge (squash) September 27, 2026 07:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant