Sandbox Escape Vulnerability in OpenSSL_Encrypt from GitHub
CVE-2026-74899
9.3CRITICAL
What is CVE-2026-74899?
OpenSSL_Encrypt versions prior to 1.4.0 are affected by a sandbox escape vulnerability in IsolatedPluginExecutor. This flaw allows attackers to traverse the Python class hierarchy through class.mro.subclasses(), granting access to restricted exec() builtins. As a result, malicious users can exploit this vulnerability to execute arbitrary OS commands, posing a significant threat to system integrity and security.
Affected Version(s)
openssl_encrypt 0 < 1.4.0
openssl_encrypt 1.4.0
