CVE-2026-2297 describes a vulnerability in CPython where the SourcelessFileLoader, responsible for handling legacy .pyc files, incorrectly bypasses io.open_code() during file reading. This oversight prevents sys.audit handlers from triggering for relevant audit events. With a CVSS score of 5.7 (Medium), this local vulnerability requires low attack complexity and user privileges, potentially leading to high integrity impact by circumventing audit logging. However, it does not directly impact confidentiality or availability. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there's minimal community discussion and media coverage, it is not on the KEV or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.13CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.4CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.