{"id":"CVE-2024-27758","aliases":["GHSA-h5cg-53g7-gqjw","PYSEC-2024-44"],"title":"RPyC's missing security check results in code execution when using numpy.array on the server-side.","summary":"RPyC's missing security check results in code execution when using numpy.array on the server-side.","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","vendor":"rpyc","product":"rpyc","ecosystem":"pip","affected":["rpyc >= 4.0.0, < 6.0.0"],"patched":["rpyc 6.0.0"],"published":"2024-03-06","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-h5cg-53g7-gqjw","references":[{"url":"https://github.com/tomerfiliba-org/rpyc/security/advisories/GHSA-h5cg-53g7-gqjw"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27758"},{"url":"https://github.com/tomerfiliba-org/rpyc/commit/9f45f8269d4106905db61d82cd529cacdb178911"},{"url":"https://github.com/tomerfiliba-org/rpyc/commit/bba1d3562e6f9f1256ec64048cc23001c0bb7516"},{"url":"https://gist.github.com/renbou/957f70d27470982994f12a1d70153d09"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/rpyc/PYSEC-2024-44.yaml"},{"url":"https://github.com/tomerfiliba-org/rpyc"},{"url":"https://github.com/tomerfiliba-org/rpyc/blob/5.3.1/rpyc/core/netref.py#L252-L255"}],"tags":["osv","pip"],"epss":0.00507,"epssPercentile":0.40635,"ingestedAt":"2026-07-08T18:25:49.984Z","slug":"CVE-2024-27758","body":"## Overview\n\nAn issue in Open Source: RPyC v.4.00 thru v.5.3.1 allows a remote attacker to execute arbitrary code via a crafted script to the `__array__` attribute component. This vulnerability was introduced in [9f45f826](https://github.com/tomerfiliba-org/rpyc/commit/9f45f8269d4106905db61d82cd529cacdb178911).\n\n### Attack Vector\nRPyC services that rely on the `__array__` attribute used by numpy are impacted. When the server-side exposes a method that calls the attribute named `__array__` for a a client provided netref (e.g., `np.array(client_netref)`), a remote attacker can craft a class which results in remote code execution\n\n### Impact\nAssuming the system exposes a method that calls the attribute `__array__`, an attacker can execute code using the vulnerable component. \n\n### Patches\nThe fix is available in RPyC 6.0.0. The major version change is because some users may need to set `allow_pickle` to `True` when migrating to RPyC 6.\n\n### Workarounds\nWhile the recommend fix is to upgrade to RPyC 6.0.0, the workaround is to [apply bba1d356 as patch.](https://github.com/tomerfiliba-org/rpyc/commit/bba1d3562e6f9f1256ec64048cc23001c0bb7516)\n\n### Affected Component\n[The affected component](https://github.com/tomerfiliba-org/rpyc/blob/5.3.1/rpyc/core/netref.py#L252-L255) is the `__array__` method constructed for `NetrefClass`.\n\n### References\n- [Original disclosure](https://gist.github.com/renbou/957f70d27470982994f12a1d70153d09) by [renbou (Artem Mikheev)](https://gist.github.com/renbou)\n- [CVE-2024-27758](https://nvd.nist.gov/vuln/detail/CVE-2024-27758)\n\n\n## Affected packages\n\n- `rpyc >= 4.0.0, < 6.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `rpyc 6.0.0`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}