---
id: CVE-2016-6903
aliases:
  - PYSEC-2017-154
title: >-
  lshell 0.9.16 allows remote authenticated users to break out of a limited
  shell and execute arbitrary commands.
summary: >-
  lshell 0.9.16 allows remote authenticated users to break out of a limited
  shell and execute arbitrary commands.
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: limited-shell
product: limited-shell
ecosystem: pip
affected:
  - limited-shell <= 0.9.16
published: '2017-04-24'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2017-154'
references:
  - url: 'http://www.securityfocus.com/bid/92591'
  - url: 'http://www.openwall.com/lists/oss-security/2016/08/22/17'
  - url: 'https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=834946'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1369345'
  - url: >-
      https://github.com/ghantoos/lshell/commit/e72dfcd1f258193f9aaea3591ecbdaed207661a0
  - url: 'https://github.com/ghantoos/lshell/issues/149'
  - url: >-
      https://github.com/ghantoos/lshell/pull/153/commits/a686f71732a3d0f16df52ef46ab8a49ee0083c68
tags:
  - osv
  - pip
epss: 0.04546
epssPercentile: 0.91158
ingestedAt: '2026-07-13T18:58:05.667Z'
---

## Overview

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

## Affected packages

- `limited-shell <= 0.9.16`

## Remediation

Refer to the advisory for the patched release.
