PT-2026-34599 · Pyspector · Pyspector

Fg0X0

·

Published

2026-04-16

·

Updated

2026-04-23

·

CVE-2026-41206

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PySpector versions prior to 0.1.8
Description The plugin security validator uses AST-based static analysis to prevent dangerous code from being loaded as plugins. The blocklist implemented in the validate plugin code() function is incomplete and can be bypassed using several Python constructs that are not checked. An attacker who can supply a plugin file can achieve arbitrary code execution within the process when that plugin is installed and executed.
Recommendations Update to version 0.1.8.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41206
GHSA-VP22-38M5-R39R

Affected Products

Pyspector