Remote Code Execution Vulnerability in Perspective 5.0.0 by Perspective
CVE-2026-67195

8.7HIGH

Key Information:

Vendor
CVE Published:
4 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-67195?

The Perspective version 5.0.0 is susceptible to a remote code execution flaw that enables unauthenticated attackers to run arbitrary command-line instructions on the host system. By leveraging crafted expression strings targeted at the PolarsVirtualServer backend, the vulnerability exposes a significant risk as it directly utilizes Python's eval() function with minimal restrictions. Attackers can manipulate Python’s object attribute traversal within the interpreter to gain access to subprocess.Popen through specially crafted protobuf messages, facilitating unauthorized command execution within the Perspective host process. This presents an urgent need for users to address the security implications associated with this vulnerability.

Affected Version(s)

perspective 0 <= 5.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christ Bowel Bouchuen
.