CVE-2026-33139Disclosure(parzivalhack / pyspector)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected by a security validation bypass in the plugin system. The validate_plugin_code() function in plugin_system.py, performs static AST analysis to block dangerous API calls before a plugin is trusted and executed. However, the internal resolve_name() helper only handles ast.Name and ast.Attribute node types, returning None for all others. When a plugin uses indirect function calls via getattr() (such as getattr(os, 'system')) the outer call's func node is of type ast.Call, causing resolve_name() to return None, and the security check to be silently skipped. The plugin incorrectly passes the trust workflow, and executes arbitrary system commands on the user's machine when loaded. This issue has been patched in version 0.1.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyspector

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
pyspector

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-04-28: 1Technical Details · 2026-04-28: 103-2104-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-04-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    GHSA-VP22-38M5-R39R: CVE-2026-33139: Arbitrary Code Execution via Sandbox Bypass in PySpector Plugin Validation PySpector versions 0.1.6 and earlier contain a critical vulnerability in the plugin security validation system. An incomplete Abstract Synt... https://cvereports.com/reports/GHSA-VP22-38M5-R39R

    Post summary

    The text announces CVE-2026-33139, a critical arbitrary code execution vulnerability in PySpector plugin validation, without providing PoC, exploit, or patch details.

    0000030
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33139 PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected b… https://www.cve.org/CVERecord?id=CVE-2026-33139 ----- Traducción: CVE-2026-33139 PyS… http://infoflow.cloud`

    Post summary

    CVE-2026-33139 is disclosed, affecting PySpector versions 0.1.6 and prior; no PoC, exploit tool, or patch information is provided.

    0000027
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33139 PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected b… https://www.cve.org/CVERecord?id=CVE-2026-33139

    Post summary

    The post merely states that CVE-2026-33139 affects PySpector up to version 0.1.6, offering no technical, patch, or exploitation details.

    00000212
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparzivalhackpyspector-python-

Explore more