Remote Code Execution Vulnerability in Perspective 5.0.0 by Perspective
CVE-2026-67195
What is CVE-2026-67195?
The Perspective version 5.0.0 is susceptible to a remote code execution flaw that enables unauthenticated attackers to run arbitrary command-line instructions on the host system. By leveraging crafted expression strings targeted at the PolarsVirtualServer backend, the vulnerability exposes a significant risk as it directly utilizes Python's eval() function with minimal restrictions. Attackers can manipulate Python’s object attribute traversal within the interpreter to gain access to subprocess.Popen through specially crafted protobuf messages, facilitating unauthorized command execution within the Perspective host process. This presents an urgent need for users to address the security implications associated with this vulnerability.
Affected Version(s)
perspective 0 <= 5.0.0
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
