Beveiligingsadvies

CVE-2021-47952

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-16 15:26:06
Laatst bijgewerkt 2026-07-28 01:47:30
Toegewezen door VulnCheck
CVSS-score 9.8
Status PUBLISHED

Beschrijving

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.