PT-2026-45829 · Pypi · Aiohttp
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions prior to 3.14.0
Description
Using the
CookieJar.load() function with untrusted input may allow arbitrary code execution. This issue is unlikely to affect many applications as most use this function with the user's own data.Recommendations
Update to version 3.14.0.
As a temporary workaround for older releases, sanitize files before loading if the application allows attacker-controlled files to be loaded.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aiohttp