VDB
Sign up
CRITICAL9.8

PYSEC-2026-523

WMAgent arbitrary code execution via a crafted dbs-client package

Quick fix

PYSEC-2026-523 — reqmgr2: upgrade to the fixed version with the command below.

pip install --upgrade 'reqmgr2>=2.0.4'

Details

WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/reqmgr2
Introduced in: 1.4.0rc2Fixed in: 2.0.4
Fixpip install --upgrade 'reqmgr2>=2.0.4'

References