HIGH 8.8 GitHub

CVE-2026-55585

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

### Summary The `qwed` package (version 5.1.1) passes attacker-controlled input directly to SymPy's `parse_expr()` function without a restricted namespace. Because `parse_expr()` internally calls Python's `eval()`, any authenticated tenant can execute arbitrary Python code inside the API server process. The attack requires only a standard user account, which is freely obtainable through the default-enabled `/auth/signup` endpoint. Successful exploitation gives the attacker full read/write acces

Affected Products

References

Published: 2026-08-25 · Source: GitHub · Feed updated: 2026-08-25
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-08-25 via GitHub. Affected: pip/qwed < 5.1.2.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.