PYSEC-2026-1695
NI MeasurementLink Python Services Improper Access Restriction vulnerability
Quick fix
PYSEC-2026-1695 — ni-measurementlink-service: upgrade to the fixed version with the command below.
pip install --upgrade 'ni-measurementlink-service>=1.1.1'Details
### Impact An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written in Python using version 1.1.0 of the `ni-measurementlink-service` Python package and all previous versions.
### Patches Upgrade all Python measurement plug-ins to use `ni-measurementlink-service` version 1.1.1 or later.
### References Visit [ni.com/info](http://www.ni.com/info) and enter the info code `cve-2023-4570` for more information.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.1.1pip install --upgrade 'ni-measurementlink-service>=1.1.1'References
- https://github.com/ni/measurementlink-python/security/advisories/GHSA-3f48-9j7q-q2gv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-4570[ADVISORY]
- https://github.com/ni/measurementlink-python/commit/3e9d45147befc9a151fca5582c64fa77c7ba1980[WEB]
- https://github.com/ni/measurementlink-python/commit/d2c73b1e0252081e1b89767aa916d73772d04dd9[WEB]
- https://github.com/ni/measurementlink-python[PACKAGE]
- https://www.ni.com/en/support/documentation/supplemental/23/improper-restriction-in-ni-measurementlink-python-services.html[WEB]
- https://pypi.org/project/ni-measurementlink-service[PACKAGE]
- https://github.com/advisories/GHSA-3f48-9j7q-q2gv[ADVISORY]