CVE-2026-93421Medium· 5.3▾ SunlitMesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /csp endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
mesop <= 1.3.3Patched in:
mesop 1.3.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34824High· 7.5Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
CVE-2025-30358High· 8.1Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
CVE-2024-45601High· 7.5Mesop has a local file Inclusion via static file serving functionality
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
CVE-2026-72847Medium· 4.6broot renders each file and directory name in its interactive tree view exactly as read from the filesystem
CVE-2026-6327Medium· 4.3IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.