asteval
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting astevalpage 1 of 1
- CVE-2025-24359HIGHCVSS 8.4EG 8.4✓ Fixed in 1.0.62025-01-24
vulnerable: 0.9 ... 1.0.5 (40 versions)
ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of…
- CVE-2026-55244MEDIUMCVSS 5.0EG 5.0✓ Fixed in 1.0.92026-08-20
vulnerable: 0.9 ... 1.0.8 (43 versions)
ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), wh…
Check whether asteval is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for asteval CVEs against the assets you own.
Start Free Scan →