PT-2026-76632 · Unknown · Openssl-Encrypt

CVE-2026-74896

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description A sandbox escape exists in the DangerousPatternVisitor AST (Abstract Syntax Tree) analyzer, which is a tool used to analyze the structure of source code. The analyzer fails to detect dunder attribute traversal techniques, where attackers use special Python attributes—such as class, bases, subclasses (), and globals—to navigate the object hierarchy. This allows unauthorized access to restricted functions and the execution of arbitrary system commands from plugin code.
Recommendations Update to version 1.4.0 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74896
GHSA-W7GR-9G4G-33MX
PYSEC-2026-3771

Affected Products

Openssl-Encrypt