CVE-2026-33054Disclosure(mesop-dev / mesop)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mesop-dev mesop systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily target files on the disk under the standard file-based runtime backend. This can result in application denial of service (via crash loops when reading non-msgpack target files as configurations), or arbitrary file manipulation. This vulnerability heavily exposes systems hosted utilizing FileStateSessionBackend. Unauthorized malicious actors could interact with arbitrary payloads overwriting or explicitly removing underlying service resources natively outside the application bounds. This issue has been fixed in version 1.2.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mesop

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-20); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
mesop

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-23: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-1903-2003-2103-2303-2503-26
Signal classification4 categories
Disclosure
342.9%
General
228.6%
Patch
114.3%
PoC
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-191
General1
2026-03-202
Patch1PoC1
2026-03-211
Disclosure1
2026-03-231
Disclosure1
2026-03-251
General1
2026-03-261
Disclosure1
Full discourse7 posts
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33054 is a critical Mesop path traversal flaw that can disrupt operations and expose business data if you have not upgraded. https://hubs.li/Q048tVbw0

    Post summary

    A new critical path traversal vulnerability (CVE-2026-33054) in Mesop is disclosed, potentially exposing business data; users are advised to upgrade to mitigate the risk.

    0000034
    29 followersView on X
  • AiSoloStudio@aisolostudio
    General

    𝕏 投稿テキスト MesopにCVSS 10.0のパストラバーサル(CVE-2026-33054)、OpenWrt mdnsにスタックBOF 2件でRCE可能性。Microsoft Copilot SSRFやPJSIP DNSパーサーBOFも。本日のCVE 200件まとめ↓ #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-03-25/

    Post summary

    The post lists several high‑severity CVEs with brief technical descriptors but offers no proof of concept, exploit code, patch information, or evidence of active exploitation.

    0000095
    2 followersView on X
  • NCIIPC India@NCIIPC
    Disclosure

    Critical Path Traversal Vulnerability has been discovered in #Mesop, a Python-based UI framework. Users are advised to follow OEM Security Advisories to remain safe! #CVE-2026-33054 https://nvd.nist.gov/vuln/detail/CVE-2026-33054

    Post summary

    A newly discovered critical path traversal vulnerability was reported in the Mesop Python UI framework; users are advised to consult OEM security advisories for mitigation.

    00000154
    8.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33054 - Critical Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrust... https://www.thehackerwire.com/vulnerability/CVE-2026-33054/ https://t.co/34TcOQGfAZ

    Post summary

    A new Path Traversal vulnerability (CVE-2026-33054) is reported as critical for Mesop versions 1.2.2 and earlier.

    0000031
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33054: CRITICAL] 🔒 Attention! Mesop UI framework versions 1.2.2 and below have a critical Path Traversal vulnerability fixed in version 1.2.3. Update now to secure your web applications.#cve,CVE-2026-33054,#cybersecurity https://cvefind.com/CVE-2026-33054

    Post summary

    The post announces that Mesop UI version 1.2.2 and below contain a critical path traversal flaw, which is fixed in 1.2.3, and urges users to update immediately.

    0000053
    604 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-33054: Mesop: Path Traversal utilizing ... Unauthenticated path traversal via state_token bypasses FileStateSessionBackend entirely - instant RCE through arbitrar... https://zerodaysignal.com/vulnerability/CVE-2026-33054 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts to CVE-2026-33054, an unauthenticated path traversal in Mesop that enables remote code execution, and links to a zero‑day signal page likely containing PoC details, with no mention of active exploitation or patch.

    0000072
    155 followersView on X
  • PulsePatch.io@pulsepatchio
    General

    Path traversal in `Mesop`'s `FileStateSessionBackend` (CVE-2026-33054) allows app DoS & file manipulation. Monitor vendor for updates. #Mesop #PathTraversal #InfoSec https://www.pulsepatch.io/posts/cve-2026-33054-mesop-path-traversal

    Post summary

    A path traversal flaw in Mesop’s FileStateSessionBackend can lead to denial of service and file manipulation; no PoC, exploit code, or vendor patch details are provided.

    0000031
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmesop-devmesop---

Explore more