OVERVIEW CVE-2026-5713 affects Python 3.15+ profiling.sampling module and asyncio introspection capabilities (3.14+), including features like "python -m asyncio ps" and "python -m asyncio pstree." The vulnerability allows an attacker to read and write addresses in a privileged process by connecting through the remote debugging feature to a malicious or compromised Python process. SEVERITY The attack requires local network access and persistence, as an attacker must repeatedly establish connections to the target process even after crashes caused by Address Space Layout Randomization (ASLR) protections. While the attack complexity is high due to these barriers, successful exploitation could result in arbitrary code execution within a privileged process, representing a significant integrity and confidentiality impact. The CVSS score is currently unavailable, though the EPSS score of 0.00017 indicates extremely low probability of exploitation in the wild relative to other vulnerabilities. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation. The vulnerability remains on the inactive Hot List, with no publicly available exploit code reported. Community attention appears minimal, consistent with the low EPSS score and the technical barriers required for successful exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.14.0, < 3.14.5CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.