access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2021-47952 CVE-2021-47952
CRITICAL
python jsonpickle 2.0.0 Remote Code Execution via py/repr
Record summary
CVE-2021-47952 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
python jsonpickleBrowse Jsonpickle / python jsonpickle | CVE List | 2.0.0 | affected |
Red Hat Ansible Automation Platform 2Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Default status: unaffected | CVE List | Version data not supplied | |
Red Hat Ansible Automation Platform 2Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Default status: unaffected | CVE List | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBpython jsonpickle 2.0.0 - Remote Code ExecutionExploitDB exploitby Adi MalyankerNot analyzed1 file
References
8RHBZ#2478170issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2478170 Product Referenceproduct
https://github.com/jsonpickle/jsonpickle Official Product Homepageproduct
https://jsonpickle.github.io/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47952 security.access.redhat.comx_sadp csaf vex
https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-47952.json ExploitDB-49585exploit
https://www.exploit-db.com/exploits/49585 VulnCheck Advisory: python jsonpickle 2.0.0 Remote Code Execution via py/reprThird-party advisory
https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-execution-via-py-repr