PYSEC-2026-1839
pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
Quick fix
PYSEC-2026-1839 — pyrage: upgrade to the fixed version with the command below.
pip install --upgrade 'pyrage>=1.2.3'Details
`pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w.
All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details.
Versions of `pyrage` before 1.2.0 lack plugin support and are therefore **not affected**.
An equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory [GHSA-32gq-x56h-299c](https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c).
Thanks to ⬡-49016 for reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c[WEB]
- https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w[WEB]
- https://github.com/woodruffw/pyrage/security/advisories/GHSA-47h8-jmp3-9f28[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-56327[ADVISORY]
- https://github.com/advisories/GHSA-4fg7-vxc8-qx5w[ADVISORY]
- https://github.com/woodruffw/pyrage[PACKAGE]
- https://pypi.org/project/pyrage[PACKAGE]
- https://github.com/advisories/GHSA-47h8-jmp3-9f28[ADVISORY]