PT-2026-76633 · Pypi · Openssl-Encrypt

CVE-2026-74899

·

Published

2026-08-17

·

Updated

2026-08-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description A sandbox escape exists in the IsolatedPluginExecutor component that exposes Python type objects within restricted exec() builtins. This allows attackers to traverse the Python class hierarchy using class . mro . subclasses () to access system functions and execute arbitrary operating system commands.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74899
GHSA-43JX-GXQ4-JPJC
GHSA-M25M-GGXG-239C
PYSEC-2026-3727

Affected Products

Openssl-Encrypt