Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-7489

23
FAUCET Score

CVE-2013-7489 describes a critical deserialization of untrusted data vulnerability in the Beaker library for Python, affecting versions up to 1.11.0. This flaw allows for arbitrary code execution, posing a significant risk to systems utilizing the library. With a CVSS score of 6.8 (Medium), the vulnerability has a low attack complexity and high impact on confidentiality, integrity, and availability, though it requires high privileges and adjacent network access. There is currently no evidence of active exploitation, nor are there public exploit modules or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.11.0CPE matchmatch criteria
cpe:2.3:a:beakerbrowser:beaker:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.12%
Probability of exploitation in next 30 days
EPSS Percentile
62.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0112 is in the 87th percentile among its peer group of 399 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

nodejspatch availablevia llm_extracted
Fixed in: 9.4.3, 9.3.5, 9.2.7, 9.1.10
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python-beaker

Vendor Advisories (3)

nodejsllm-nodejs-b263506120f02d37CRITICAL

Third-Party Package Updates in Splunk Enterprise - July 2025

Jul 7, 2025
pipGHSA-3cwm-7jmm-774wmedium

Deserialization of Untrusted Data in Beaker

May 5, 2022
redhatCVE-2013-7489Moderate

python-beaker: Deserialization of Untrusted Data which can lead to Arbitrary code execution

May 14, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / bbangert/beaker/issues/191
Third Party Advisory
openwall.com / lists/oss-security/2020/05/14/11
Mailing ListThird Party Advisory