CVE-2019-17526

CRITICAL

SageMath Sage Cell Server - OS Command Injection via Python Code Execution

Title source: llm
STIX 2.1

Description

An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE: the vendor's position is that the product is "vulnerable by design" and the current behavior will be retained

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0300
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-94
Status published
Products (1)
sagemath/sagemathcell
Published Oct 18, 2019
Tracked Since Feb 18, 2026