epyt-flow
EPyT-Flow -- EPANET Python Toolkit - Flow
Activity
- Latest release
- 1mo ago
- Total releases
- 29
- Cadence
- ~24 days
- Last 12 months
- 7
Reach
- Stars
- —
Details
- License
- MIT
- First release
- May 10, 2024
| Version | Released | |
|---|---|---|
0.17.2
patch
| ||
0.17.1
patch
| ||
0.17.0
minor
| ||
0.16.1
patch
| ||
0.16.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.15.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.15.0b1
pre
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.14.2
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.14.1
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.3
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.2
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2026-25632
PYSEC-2026-330
GHSA-74vm-8frp-7w68
Jun 29, 2026
EPyT-Flow vulnerable to unsafe JSON deserialization (__type__)
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactEPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. PatchesEPyT-Flow has been patched in 0.16.1 -- affects all versions <= 0.16.0 WorkaroundsDo not load any JSON from untrusted sources and do not expose the REST API. CreditsEPyT-Flow thanks Jarrett Chan (@syphonetic) for detecting and reporting the bug. Affected versions
0.1.0
0.1.1
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.15.0
0.15.0b1
+ 13 more Show less
0.16.0
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.8.1
0.9.0
Fixed in
0.16.1
References
Updated Jul 01, 2026 · Source: OSV.dev |