Arbitrary Code Injection Affecting webpy package, versions <1:0.40-2ubuntu0.1~esm1


Severity

Recommended
0.0
medium
0
10

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2004-WEBPY-9833247
  • published17 Jun 2026
  • disclosed19 Apr 2025

Introduced: 19 Apr 2025

CVE-2025-3818  (opens in a new tab)
CWE-74  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade Ubuntu:20.04 webpy to version 1:0.40-2ubuntu0.1~esm1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream webpy package and not the webpy package as distributed by Ubuntu. See How to fix? for Ubuntu:20.04 relevant fixed versions and status.

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS Base Scores

version 3.1