← Back to CVE search

CVE-2026-67195

Description

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python-s eval() with only __builtins__={} cleared. Attackers can exploit Python object attribute traversal through the interpreter-s loaded class list to reach subprocess.Popen via a TableValidateExprReq or TableMakeViewReq protobuf message, achieving arbitrary command execution in the Perspective host process.

CVSS 8.8EPSS 1.1560000000000001%Risk 0.97
View source
Published
2026-08-04 15:16:40
Last modified
2026-08-04 16:16:27
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H