joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpypickle::NumpyArrayWrapper().readarray(). NOTE: this is disputed by the supplier because NumpyArrayWrapper is only used during caching of trusted content.