CVE-2025-30358
Last modified
CVE-2025-30358 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequences like remote code execution when gadgets are available. Users should upgrade to version 0.14.1 to obtain a fix for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30358?
How severe is CVE-2025-30358?
How do I fix CVE-2025-30358?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30352Directus is a real-time API and App dashboard for managing S…5.3
- CVE-2025-30353Directus is a real-time API and App dashboard for managing S…7.5
- CVE-2025-30354Bruno is an open source IDE for exploring and testing APIs. …4.3
- CVE-2025-30355Synapse is an open source Matrix homeserver implementation. …7.5
- CVE-2025-30356CryptoLib provides a software-only solution using the CCSDS …9.8
- CVE-2025-30357NamelessMC is a free, easy to use & powerful website softwar…6.8
- CVE-2025-30359webpack-dev-server allows users to use webpack with a develo…5.9
- CVE-2025-3036A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2025-30360webpack-dev-server allows users to use webpack with a develo…6.5
- CVE-2025-30361WeGIA is a Web manager for charitable institutions. A securi…9.8
- CVE-2025-30362WeGIA is a Web manager for charitable institutions. A stored…5.4
- CVE-2025-30363WeGIA is a Web manager for charitable institutions. A stored…5.4
Are you affected by CVE-2025-30358?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
