PT-2026-60075 · Dirac · Dirac
CVE-2026-45579
·
Published
2026-07-13
·
Updated
2026-07-23
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DIRAC versions prior to 8.0.79
DIRAC versions prior to 9.0.22
DIRAC versions prior to 9.1.10
Description
Remote code execution is possible in RequestManager because the
export getRequestCountersWeb() function passes parameters directly to the database instance. When the groupingAttribute variable is unrecognized, the system prepends Request. to it and passes the result into an eval() call. An authenticated user can provide a dunder string applicable to the Request object to access functions in the os module and execute commands in the server context. This can lead to a full system compromise, including access to the dirac.cfg file, database passwords, and stored proxies and tokens. Additionally, attackers may be able to remove evidence of the exploit from local logs.Recommendations
Update to version 8.0.79 or later.
Update to version 9.0.22 or later.
Update to version 9.1.10 or later.
Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dirac