CVE-2026-42301High· 7.3▾ TwilightA flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.2%
Last analysed / modified upstream
7.8 → 7.3
A flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because pyp2spec writes PyPI package metadata, such as the summary field, into the generated spec file without properly escaping RPM macro directives. When a packager subsequently runs rpmbuild, these unescaped directives are evaluated, leading to the execution of arbitrary commands.
pyp2spec: pyp2spec: Arbitrary command execution via unescaped RPM macro directives. Released 2026-05-09, updated 2026-09-18.
Not affected:
Refer to the advisory for fix availability.
Affected packages:
pyp2spec < 0.14.1Patched in:
pyp2spec 0.14.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror
CVE-2026-94184High· 8.1A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support