PT-2026-46099 · Pypi · Aiohttp

Publicado

2026-06-03

·

Atualizado

2026-06-03

CVSS v3.1

6.4

Média

VetorAV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L

Summary

Using CookieJar.load() with untrusted input may allow arbitrary code execution.

Impact

Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications.

Workaround

If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitise the files before loading.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-JG22-MG44-37J8

Produtos afetados

Aiohttp