Rahmi Demir ⭐⭐⭐⭐⭐[verified]@rahmid3mirDisclosure
A new CVE-2026-12003 LPE flaw in Windows‑based Python installations via the VPATH mechanism has been disclosed, with technical details and mitigation recommendations.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The post reports that attackers are actively exploiting CVE-2026‑12003 by manipulating VPATH variables to achieve privilege escalation on Windows Python installations.
Can Artuc[verified]@canartucDisclosure
The post discloses that Windows users of CPython 3.11.15 through 3.15.0b2 (and earlier) are vulnerable to CVE‑2026‑12003 via library injection, lists the affected releases and CVSS score, and urges rapid patching.
Can Artuc[verified]@canartucDisclosure
The tweet announces CVE‑2026‑12003, outlining how CPython’s in‑tree build detection can be abused to inject libraries by low‑privilege users, but does not provide a PoC, exploit, or patch.
Bishop Fox@bishopfoxDisclosure
Bishop Fox released an advisory for CVE‑2026‑12003, noting a Windows‑specific Python LPE vulnerability in versions 3.11‑3.15, without any PoC, exploit code, active exploitation evidence, or patch information.
Open Source Security mailing list@oss_securityDisclosure
A new CVE for CPython is disclosed, noting that in‑tree development search paths can be enabled without altering the install directory; technical details are shared via the Openwall mailing list.
Behk@behkfoxDisclosure
Bishop Fox reports a new Windows‑specific Python vulnerability (CVE-2026-12003) affecting versions 3.11–3.15 that can enable local privilege escalation under certain conditions.
CVE@CVEnewGeneral
The text references CVE-2026-12003 with a brief mention of a build‑time variable and a link to the official record, but it provides no concrete details about exploitation, patching, or technical specifics.