PT-2026-50440 · Pypi · Statemachine

·

CVE-2026-47103

·

Published

2026-06-17

·

Updated

2026-08-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Python StateMachine versions 3.0.0 through 3.1.x
Description An issue exists where the library evaluates expressions from SCXML documents unsafely. The SCXMLProcessor passes attacker-controlled expression strings from <data expr="..."> attributes through a call chain into Python's built-in eval() function without sandboxing. This allows for remote code execution in the context of the hosting process when a malicious SCXML document is parsed.
Recommendations Update to version 3.2.0.

Exploit

Fix

RCE

Code Injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47103
GHSA-V4JC-PM6R-3VJ8
PYSEC-2026-506

Affected Products

Statemachine