—
PYSEC-2026-2048
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
Quick fix
PYSEC-2026-2048 — whoogle-search: upgrade to the fixed version with the command below.
pip install --upgrade 'whoogle-search>=0.9.1'Details
An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-53305[ADVISORY]
- https://github.com/benbusby/whoogle-search/commit/223f00c3c0533423114f99b30c561278bc0b42ba[WEB]
- https://fern89.github.io/posts/whoogle-rce[WEB]
- https://gist.github.com/fern89/ca5fe76ad81b4bc363e7341e523a1651[WEB]
- https://github.com/benbusby/whoogle-search[PACKAGE]
- https://pypi.org/project/whoogle-search[PACKAGE]
- https://github.com/advisories/GHSA-2689-cw26-6cpj[ADVISORY]