PT-2026-34599 · Pyspector · Pyspector
Fg0X0
·
Published
2026-04-16
·
Updated
2026-04-23
·
CVE-2026-41206
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PySpector versions prior to 0.1.8
Description
The plugin security validator uses AST-based static analysis to prevent dangerous code from being loaded as plugins. The blocklist implemented in the
validate plugin code() function is incomplete and can be bypassed using several Python constructs that are not checked. An attacker who can supply a plugin file can achieve arbitrary code execution within the process when that plugin is installed and executed.Recommendations
Update to version 0.1.8.
Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyspector