CVE-2026-33057 is a critical Unrestricted Remote Code Execution (RCE) vulnerability affecting Mesop, a Python-based UI framework, in versions 1.2.2 and below. This flaw allows an unauthenticated attacker to execute arbitrary Python code on the host machine by sending a specially crafted web request to an exposed endpoint, leading to complete system compromise. Rated with a CVSS score of 9.8 (CRITICAL), it has a network attack vector with low complexity and requires no user interaction or privileges. There is currently no evidence of active exploitation, nor is public exploit code available, with minimal community discussion. Organizations using affected versions should upgrade to Mesop 1.2.3 or higher immediately to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.3CPE matchmatch criteria | cpe:2.3:a:mesop-dev:mesop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.