Description
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/mesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48
Patch x_refsource_misc
https://github.com/mesa/mesa/commit/c35b8cd67fc89dd680ae218e49b77f6e1ee07a27
Scores
CVSS v3
8.3
EPSS
0.0013
EPSS Percentile
31.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-94
Status
published
Products (1)
mesa_project/mesa
< 3.5.0
Published
Mar 06, 2026
Tracked Since
Mar 07, 2026