logo

CVE-2025-50817 future

Package

Manager: pip
Name: future
Vulnerable Version: >=0.14.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

EPSS: 0.00036 pctl0.09008

Details

Python-Future Module Arbitrary Code Execution via Unintended Import of test.py A vulnerability in Python-Future modules 0.14.0 and above allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

Metadata

Created: 2025-08-14T18:31:30Z
Modified: 2025-08-22T23:18:31Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-xqrq-4mgf-ff32/GHSA-xqrq-4mgf-ff32.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-xqrq-4mgf-ff32
Finding: F063
Auto approve: 1