HIGH8.8
PYSEC-2026-1476
js2py allows remote code execution
Details
An issue in the component `js2py.disable_pyimport()` of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/js2py
Introduced in:
0No fixed version published yet for js2py (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-28397[ADVISORY]
- https://github.com/PiotrDabkowski/Js2Py/pull/323[WEB]
- https://github.com/Marven11[WEB]
- https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape[WEB]
- https://github.com/PiotrDabkowski/Js2Py[PACKAGE]
- https://pypi.org/project/js2py[PACKAGE]
- https://github.com/advisories/GHSA-h95x-26f3-88hr[ADVISORY]