SageMath is an open-source computer algebra and mathematics software platform whose vulnerability footprint centers on code-injection and command-injection weaknesses in its core computational engine and web-accessible cell interface. These input-handling and code-generation issues reflect the inherent risk of systems that parse and execute user-supplied mathematical expressions and shell commands. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sagemath over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17526CRITICAL An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can | Oct 18, 2019 | 9.8 | 28 | NO | NO |
CVE-2023-29465MEDIUM SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user | Apr 6, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sagemath.
Media articles that mention a CVE ID that affects a product developed by Sagemath — matched by CVE ID, not by vendor name.