VDB
Sign up
CRITICAL9.8

PYSEC-2026-557

Salesforce Uni2TS has a Code Injection vulnerability

Quick fix

PYSEC-2026-557 — uni2ts: upgrade to the fixed version with the command below.

pip install --upgrade 'uni2ts>=2.0.0'

Details

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/uni2ts
Introduced in: 0Fixed in: 2.0.0
Fixpip install --upgrade 'uni2ts>=2.0.0'

References