MEDIUM5.3
PYSEC-2026-1215
XPixelGroup BasicSR Command Injection
Details
XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/basicsr
Introduced in:
0No fixed version published yet for basicsr (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-27763[ADVISORY]
- https://gist.github.com/aydinnyunus/40e1d8a3b529261ae654ff4891f1e192[WEB]
- https://github.com/XPixelGroup/BasicSR[PACKAGE]
- https://github.com/XPixelGroup/BasicSR/blob/master/basicsr/utils/dist_util.py#L44[WEB]
- https://pypi.org/project/basicsr[PACKAGE]
- https://github.com/advisories/GHSA-86w8-vhw6-q9qq[ADVISORY]