PT-2026-57976 · Dirac · Dirac

CVE-2026-61667

·

Published

2026-07-13

·

Updated

2026-07-23

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DIRAC versions prior to 8.0.79 DIRAC versions prior to 9.0.22 DIRAC versions prior to 9.1.10
Description An authenticated user can achieve remote code execution on the server due to a flaw in the FileCatalog DatasetManager. The checkDataset() function passes the datasets argument to the checkDataset() function, which uses an unescaped f-string to construct a database query. This SQL injection allows an attacker to control the query result, which is subsequently passed to the eval() function, leading to arbitrary code execution. This can result in a full system compromise, including access to configuration files, database passwords, and stored proxies or tokens.
Recommendations Update to version 8.0.79 or later. Update to version 9.0.22 or later. Update to version 9.1.10 or later.

Fix

SQL injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61667
GHSA-M4M7-4CW8-62J6
PYSEC-2026-3463

Affected Products

Dirac