Arbitrary Code Injection Affecting mesop package, versions [,1.2.3)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
Exploit Maturity
Proof of Concept
EPSS
5.29% (92nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary Code Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-MESOP-17751643
  • published1 Jul 2026
  • disclosed29 Jun 2026
  • creditUnknown

Introduced: 29 Jun 2026

CVE-2026-33057  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade mesop to version 1.2.3 or higher.

Overview

mesop is a Build UIs in Python

Affected versions of this package are vulnerable to Arbitrary Code Injection due to an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings unconditionally without authentication measures, yielding standard Unrestricted Remote Code Execution. Any individual capable of routing HTTP logic to this server block will gain explicit host-machine command rights.

CVSS Base Scores

version 4.0
version 3.1