VDB
Sign up
—

PYSEC-2026-1067

Zope Command Execution Vulnerability

Quick fix

PYSEC-2026-1067 — zope2: upgrade to the fixed version with the command below.

pip install --upgrade 'zope2>=2.12.20'

Details

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the `p_` class in `OFS/misc_.py` and the use of Python modules.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/zope2
Introduced in: 2.12.0Fixed in: 2.12.20
Fixpip install --upgrade 'zope2>=2.12.20'

References