Unrestricted Remote Code Execution in Mesop Python Framework
CVE-2026-33057
Key Information:
Badges
What is CVE-2026-33057?
The Mesop UI framework, used for building web applications, contains a significant vulnerability in its ai/testing module. This flaw permits the ingestion of untrusted Python code without any authentication measures, leading to Unrestricted Remote Code Execution. By exploiting the /exec-py endpoint, malicious users can send base64 encoded payloads that are executed directly, granting control over the host machine. This critical issue is present in versions 1.2.2 and earlier, highlighting the importance of upgrading to version 1.2.3, which includes a fix.
Affected Version(s)
mesop < 1.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
