CVE-2026-30960Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations functionalities. The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Function Interface). Due to Improper Input Validation and External Control of Code Generation, an attacker can supply malicious parameters or instruction sequences through the CFFI layer. Since the library often operates with elevated privileges or within high-performance computing contexts, this allows for Arbitrary Code Execution (ACE) at the privilege level of the host process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-269CWE-695CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-10: 2Technical Details · 2026-03-10: 303-1003-16
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure1Patch2
2026-03-161
General1
Full discourse4 posts
  • Vulert@vulert_official
    Patch

    🚨 RSSN CVE-2026-30960: improper input validation in the JIT engine could allow arbitrary code execution. Update to RSSN 0.2.9+ ASAP; apply workarounds to reduce exposure until patched. 🔍 https://vulert.com/vuln-db/CVE-2026-30960 #CyberSecurity #AppSec #Vulert https://t.co/pDTpAE0Yz5

    Post summary

    The tweet announces CVE-2026-30960’s arbitrary code execution flaw and urges a patch or workaround.

    0001038
    124 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30960 rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations funct… https://www.cve.org/CVERecord?id=CVE-2026-30960

    Post summary

    The passage merely introduces CVE-2026-30960 and briefly describes the impacted Rust library, without providing additional technical details, exploitation evidence, or mitigation information.

    00000209
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30960: RSSN has Arbitrary Code Executio... JIT engines with unvalidated CFFI input are basically remote shells with extra steps - HPC contexts make this a cluster... https://zerodaysignal.com/vulnerability/CVE-2026-30960 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-30960, noting an arbitrary code execution flaw in JIT engines that could allow remote shells, but contains no PoC, exploit, patch, or active exploitation claims.

    0000049
    142 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical RCE vulnerability (CVE-2026-30960) affects `rssn` via its C-FFI interface. Update to 0.2.9+ to mitigate. #infosec #RCE https://www.pulsepatch.io/posts/cve-2026-30960-rssn-arbitrary-code-execution

    Post summary

    A critical RCE exists in rssn via the C-FFI interface; updating to version 0.2.9+ mitigates the issue.

    0000033
    1 followersView on X

Explore more