CVE-2025-50817 – future
Package
Manager: pip
Name: future
Vulnerable Version: >=0.14.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
EPSS: 0.00036 pctl0.09008
Details
Python-Future Module Arbitrary Code Execution via Unintended Import of test.py A vulnerability in Python-Future modules 0.14.0 and above allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.
Metadata
Created: 2025-08-14T18:31:30Z
Modified: 2025-08-22T23:18:31Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-xqrq-4mgf-ff32/GHSA-xqrq-4mgf-ff32.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-xqrq-4mgf-ff32
Finding: F063
Auto approve: 1