logo

New R Programming Vulnerability Exposes Projects to Supply Chain Attacks

ID: c0934a93-b1c5-506f-9485-04716ccd5dea

STIX ID: report--c0934a93-b1c5-506f-9485-04716ccd5dea

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-29

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A high-severity (CVSS 8.8) deserialization vulnerability in R (CVE-2024-27322) enables arbitrary code execution when malicious .rds/.rdx files are deserialized or when compromised R packages are loaded, creating a supply-chain risk via repositories such as CRAN. The issue stems from promise objects and lazy evaluation; it was fixed in R 4.4.0 (released April 24, 2024) and is the subject of a CERT/CC advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.