{"id":"GHSA-jx3q-5rgf-vrrr","summary":"xalpha vulnerable to Remote Code Execution","details":"xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE). User input is not properly checked to be numerical values prior to being evaluated.","aliases":["CVE-2023-37659","PYSEC-2023-116"],"modified":"2024-11-19T19:24:33.513461Z","published":"2023-07-11T15:31:18Z","database_specific":{"github_reviewed_at":"2023-07-11T22:46:05Z","nvd_published_at":"2023-07-11T15:15:20Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37659"},{"type":"WEB","url":"https://github.com/refraction-ray/xalpha/issues/175"},{"type":"WEB","url":"https://github.com/refraction-ray/xalpha/commit/6dceaa159a1a319d750ade20a4595956876657b6"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/xalpha/PYSEC-2023-116.yaml"},{"type":"PACKAGE","url":"https://github.com/refraction-ray/xalpha"}],"affected":[{"package":{"name":"xalpha","ecosystem":"PyPI","purl":"pkg:pypi/xalpha"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.11.4"},{"fixed":"0.11.9"}]}],"versions":["0.11.4","0.11.5","0.11.6","0.11.7","0.11.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-jx3q-5rgf-vrrr/GHSA-jx3q-5rgf-vrrr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}