CVE-2021-47952

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-16 16:16

Updated : 2026-07-15 02:17


NVD link : CVE-2021-47952

Mitre link : CVE-2021-47952

CVE.ORG link : CVE-2021-47952


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-502

Deserialization of Untrusted Data