CVE-2026-42301Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generated spec file without escaping RPM macro directives. When a packager then runs rpmbuild, those directives get evaluated, so a malicious package can execute arbitrary commands on the build machine. This issue has been patched in version 0.14.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-11: 1Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-09: 205-0905-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure2
2026-05-111
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42301 📊 Severity: 7.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42301 #CVE-2026-42301 #CVE #High #CyberSecurity #InfoSec https://t.co/RDj0U6f3M9

    Post summary

    A brief CVE alert for CVE-2026-42301 that provides its severity rating, a high risk level, and a link to the NVD entry, with no additional technical or exploit details.

    0000049
    157 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42301 pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into… https://www.cve.org/CVERecord?id=CVE-2026-42301

    Post summary

    This text discloses an issue with pyp2spec where, before version 0.14.1, it incorrectly wrote PyPI package metadata into the generated Fedora RPM spec file.

    0000057
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42301 Arbitrary Command Execution in pyp2spec via Unescaped RPM Macro D... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42301 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    Tweet announces CVE-2026-42301 as an arbitrary command execution vulnerability in pyp2spec via unescaped RPM macro, providing only a headline and link to details, with no PoC, exploit, or patch information.

    0000046
    4.0K followersView on X

Explore more