uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.5epss 0.2%
de la publicación al arma28 días
Publicada en NVD18 jul
1ª PoC+28d
probabilidad de explotación
0.2%top 87% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. An attacker who can supply a crafted ROOT file can place Python expression-breaking content into a streamer metadata field. When uproot generates and invokes the corresponding reader method, the injected Python expression is evaluated in the context of the process opening the file, resulting in arbitrary Python code execution in applications that open or process attacker-controlled ROOT files with affected uproot code paths.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
scikit-hep · uprootPoCs públicas encontradas — 1
githubgithub.com/SaiTeja-Erukude/CVE-2026-9147-uproot-rce★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/scikit-hep/uproot5https://github.com/scikit-hep/uproot5/commit/c045c2824295d907d2e705f31110c742928e50e7https://github.com/scikit-hep/uproot5/security/advisories/GHSA-6946-mq52-g438https://www.vulncheck.com/advisories/uproot-and-before-code-injection-via-tstreamerinfo-metadata