asteval vulnerabilities
CVEs whose affected-version data names the asteval package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-55244Medium· 5.0PoCASTEVAL is an evaluator of Python expressions and statements
ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), …
▾ Twilightlmfit · astevalEPSS 0.19%via NVD
GHSA-9w56-46f6-3qhxMedium· 5.5asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
▾ Sunlitasteval · astevalvia OSV
CVE-2025-24359High· 8.4ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
▾ Twilightasteval · astevalEPSS 0.27%via OSV