CVE-2023-26145Disclosure(derrickgilland / pydash)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects. **Note:** The pydash.objects.invoke() method is vulnerable to Command Injection when the following prerequisites are satisfied: 1) The source object (argument 1) is not a built-in object such as list/dict (otherwise, the __init__.__globals__ path is not accessible) 2) The attacker has control over argument 2 (the path string) and argument 3 (the argument to pass to the invoked method) The pydash.collections.invoke_map() method is also vulnerable, but is harder to exploit as the attacker does not have direct control over the argument to be passed to the invoked function.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-77CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pydash

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
pydash

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-07: 1Technical Details · 2026-05-07: 105-07
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 #CSS Parser gem, MITM #CSS Injection, #CVE-2023-26145 (Medium) https://dailycve.com/css-parser-gem-mitm-css-injection-cve-2023-26145-medium/

    Post summary

    The tweet announces the CVE‑2023‑26145 vulnerability in the CSS Parser gem, describing it as a MITM CSS injection with medium severity, but it does not provide a PoC, exploit, or patch details.

    0000053
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appderrickgillandpydash---

Explore more