The NumPy library relies on unsafe default usage of a Python module that could lead to remote code execution in the context of the affected application. The ‘pickle’ module is used for transforming Python object structures into a format that can be stored on disk or in databases. The issue was raised on January 16 and affects NumPy versions 1.10 (released in 2015) through 1.16, which is the latest release at the moment, released on January 14. Efforts are underway to deliver a fix and the development team is working on a fix.
Source: https://www.bleepingcomputer.com/news/security/numpy-is-awaiting-fix-for-critical-remote-code-execution-bug/