<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 20:26:28 +0000</lastBuildDate>
    <item>
      <title>GHSA-vp47-9734-prjw — ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox Escape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vp47-9734-prjw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asteval&lt;/p&gt;
&lt;p&gt;### Summary
If an attacker can control the input to the asteval library, they can bypass its safety restrictions and execute arbitrary Python code within the application&amp;#39;s context.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is rooted in how `asteval` performs attribute access verification. In particular, the [`on_attribute`](https://github.com/lmfit/asteval/blob/8d7326df8015cf6a57506b1c2c167a1c3763e090/asteval/asteval.py#L565) node handler prevents access to attributes that are either present in the `UNSAFE_ATTRS` list or are formed by names starting and ending with `__`, as shown in the code snippet below:&lt;/p&gt;
&lt;p&gt;```py
    def on_attribute(self, node):    # (&amp;#39;value&amp;#39;, &amp;#39;attr&amp;#39;, &amp;#39;ctx&amp;#39;)
        &amp;#34;&amp;#34;&amp;#34;Extract attribute.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;ctx = node.ctx.__class__
        if ctx == ast.Store:
            msg = &amp;#34;attribute for storage: shouldn&amp;#39;t be here!&amp;#34;
            self.raise_exception(node, exc=RuntimeError, msg=msg)&lt;/p&gt;
&lt;p&gt;sym = self.run(node.value)
        if ctx == ast.Del:
            return delattr(sym, node.attr)
        #
        unsafe = (node.attr in UNSAFE_ATTRS or
                 (node.attr.startswith(&amp;#39;__&amp;#39;) and node.attr.endswith(&amp;#39;__&amp;#39;)))
        if not unsafe:
            for dtype, attrlist in UNSAFE_ATTRS_DTYPES.items():
                unsafe = isinstance(sym, dtype) and node.attr in attrlist
                if unsafe:
                    break
        if unsafe:
            msg = f&amp;#34;no safe attribute &amp;#39;{node.attr}&amp;#39; for {repr(sym)}&amp;#34;
            self.raise_exception(node, exc=AttributeError, m…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: asteval&lt;/p&gt;
&lt;p&gt;### Summary
If an attacker can control the input to the asteval library, they can bypass its safety restrictions and execute arbitrary Python code within the application&amp;#39;s context.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is rooted in how `asteval` performs attribute access verification. In particular, the [`on_attribute`](https://github.com/lmfit/asteval/blob/8d7326df8015cf6a57506b1c2c167a1c3763e090/asteval/asteval.py#L565) node handler prevents access to attributes that are either present in the `UNSAFE_ATTRS` list or are formed by names starting and ending with `__`, as shown in the code snippet below:&lt;/p&gt;
&lt;p&gt;```py
    def on_attribute(self, node):    # (&amp;#39;value&amp;#39;, &amp;#39;attr&amp;#39;, &amp;#39;ctx&amp;#39;)
        &amp;#34;&amp;#34;&amp;#34;Extract attribute.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;ctx = node.ctx.__class__
        if ctx == ast.Store:
            msg = &amp;#34;attribute for storage: shouldn&amp;#39;t be here!&amp;#34;
            self.raise_exception(node, exc=RuntimeError, msg=msg)&lt;/p&gt;
&lt;p&gt;sym = self.run(node.value)
        if ctx == ast.Del:
            return delattr(sym, node.attr)
        #
        unsafe = (node.attr in UNSAFE_ATTRS or
                 (node.attr.startswith(&amp;#39;__&amp;#39;) and node.attr.endswith(&amp;#39;__&amp;#39;)))
        if not unsafe:
            for dtype, attrlist in UNSAFE_ATTRS_DTYPES.items():
                unsafe = isinstance(sym, dtype) and node.attr in attrlist
                if unsafe:
                    break
        if unsafe:
            msg = f&amp;#34;no safe attribute &amp;#39;{node.attr}&amp;#39; for {repr(sym)}&amp;#34;
            self.raise_exception(node, exc=AttributeError, m…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vp47-9734-prjw</guid>
    </item>
  </channel>
</rss>
