Arbitrary Code Execution in QWED Open-Source AI Verification Infrastructure
CVE-2026-55585

8.8HIGH

Key Information:

Vendor

Qwed-ai

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55585?

The QWED verification infrastructure, an open-source tool for deterministic validation of large language model outputs, has a vulnerability that enables arbitrary code execution via user-controlled math expressions. In versions prior to 5.1.2, the system does not adequately restrict the execution of potentially harmful commands by passing unvalidated math expressions directly to the SymPy library. This oversight allows malicious users with valid tenant keys to send crafted requests that can execute arbitrary Python code, manipulate files, and destabilize services across shared deployments. The vulnerability has been addressed in version 5.1.2.

Affected Version(s)

qwed-verification < 5.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.