GHSA-gv3j-fjgf-469vCriticalCVSS 9.8

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to...

Published
May 16, 2026
Last Modified
May 16, 2026

🔗 CVE IDs covered (1)

📋 Description

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.

🔗 References (6)