VDB
Sign up
CRITICAL9.8

PYSEC-2026-1839

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

Quick fix

PYSEC-2026-1839 — pyrage: upgrade to the fixed version with the command below.

pip install --upgrade 'pyrage>=1.2.3'

Details

`pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w.

All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details.

Versions of `pyrage` before 1.2.0 lack plugin support and are therefore **not affected**.

An equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory [GHSA-32gq-x56h-299c](https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c).

Thanks to ⬡-49016 for reporting this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyrage
Introduced in: 1.2.0Fixed in: 1.2.3
Fixpip install --upgrade 'pyrage>=1.2.3'

References