/Vulnerability Library

Mesop AI Sandbox <= 1.2.2 - Remote Code Execution

CVE-2026-33057
Verified

Description

Mesop <= 1.2.2 contains an unrestricted remote code execution caused by unauthenticated ingestion and execution of base64-encoded Python code in the /exec-py endpoint of ai/testing module, letting attackers execute arbitrary commands on the host, exploit requires HTTP access to the server.

Severity

Critical

CVSS Score

9.8

Exploit Probability

4%

Affected Product

mesop

Published Date

April 26, 2026

Template Author

sammiee5311, liyander

CVE-2026-33057.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-33057
CWE ID:
cwe-94

References

https://github.com/mesop-dev/mesop/security/advisories/GHSA-gjgx-rvqr-6w6vhttps://nvd.nist.gov/vuln/detail/CVE-2026-33057

Remediation Steps

Upgrade to version 1.2.3 or later.