CVE-2023-26145
Last modified
CVE-2023-26145 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. EPSS estimates a 2.92% chance of exploitation in the next 30 days.
Description
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects. **Note:** The pydash.objects.invoke() method is vulnerable to Command Injection when the following prerequisites are satisfied: 1) The source object (argument 1) is not a built-in object such as list/dict (otherwise, the __init__.__globals__ path is not accessible) 2) The attacker has control over argument 2 (the path string) and argument 3 (the argument to pass to the invoked method) The pydash.collections.invoke_map() method is also vulnerable, but is harder to exploit as the attacker does not have direct control over the argument to be passed to the invoked function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Derrickgilland | Pydash | < 6.0.0 |
References
- https://gist.github.com/CalumHutton/45d33e9ea55bf4953b3b31c84703dfcaExploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-PYTHON-PYDASH-5916518Third Party Advisory
- https://gist.github.com/CalumHutton/45d33e9ea55bf4953b3b31c84703dfcaExploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-PYTHON-PYDASH-5916518Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26145?
How severe is CVE-2023-26145?
How do I fix CVE-2023-26145?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-2614Cross-site Scripting (XSS) - DOM in GitHub repository pimcor…5.4
- CVE-2023-26140Versions of the package @excalidraw/excalidraw from 0.0.0 ar…6.1
- CVE-2023-26141Versions of the package sidekiq before 7.1.3 are vulnerable …4.9
- CVE-2023-26142All versions of the package crow are vulnerable to HTTP Resp…6.1
- CVE-2023-26143Versions of the package blamer before 1.0.4 are vulnerable t…9.1
- CVE-2023-26144Versions of the package graphql from 16.3.0 and before 16.8.…5.3
- CVE-2023-26146All versions of the package ithewei/libhv are vulnerable to …6.1
- CVE-2023-26147All versions of the package ithewei/libhv are vulnerable to …6.1
- CVE-2023-26148All versions of the package ithewei/libhv are vulnerable to …5.3
- CVE-2023-26149Versions of the package quill-mention before 4.0.0 are vulne…6.1
- CVE-2023-2615Cross-site Scripting (XSS) - Reflected in GitHub repository …5.4
- CVE-2023-26150Versions of the package asyncua before 0.9.96 are vulnerable…7.5
Are you affected by CVE-2023-26145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
