CVE-2026-41206 is a code injection vulnerability in PySpector, a Python static analysis security testing framework. The flaw resides in the plugin security validator's incomplete AST-based blocklist, which fails to prevent dangerous Python constructs from being loaded as plugins. An attacker who supplies a malicious plugin file can achieve arbitrary code execution within the PySpector process upon installation and execution. The vulnerability affects PySpector versions prior to 0.1.8, which contains the fix. The attack requires local access to supply a plugin file, making it a local code execution vector with relatively low complexity. The potential impact is severe, as successful exploitation grants arbitrary code execution within the PySpector process, potentially compromising the security analysis environment and any systems it interacts with. The FAUCET Risk Score of 36.0/100 indicates moderate concern despite the low EPSS percentile score. The vulnerability is marked as active on the Hot List but has not been added to the Known Exploited Vulnerabilities catalog, suggesting no confirmed active exploitation in the wild. Community attention appears limited, with no publicly disclosed exploit code readily available. Organizations running PySpector should upgrade to version 0.1.8 or later immediately, particularly in environments where untrusted users may supply plugins.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.8CPE matchmatch criteria | cpe:2.3:a:parzivalhack:pyspector:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.