Record summary

CVE-2021-47952 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List2.0.0affected

Red Hat Ansible Automation Platform 2

Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Ansible Automation Platform 2

Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBpython jsonpickle 2.0.0 - Remote Code ExecutionExploitDB exploitby Adi MalyankerNot analyzed1 file
ExploitDB

PoC details

References

8