mesop
Rapidly build AI apps in Python
Activity
- Latest release
- 4w ago
- Total releases
- 106
- Cadence
- ~4 days
- Last 12 months
- 24
Reach
- Stars
- 6.6k
Details
- License
- Apache-2.0
- First release
- Dec 13, 2023
| Version | Released | |
|---|---|---|
1.3.5
patch
| ||
1.3.4
patch
| ||
1.3.3
patch
| ||
1.3.2
patch
| ||
1.3.0
minor
| ||
1.3.0rc2
pre
| ||
1.3.0rc1
pre
| ||
1.2.7
patch
| ||
1.2.7rc1
pre
| ||
1.2.6rc2
pre
| ||
1.2.5
patch
| ||
1.2.5rc1
pre
1 CVE
CVE-2026-34824
PYSEC-2026-2204
GHSA-3jr7-6hqp-x679
Apr 03, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework. This issue has been patched in version 1.2.5. Affected versions
1.2.3
1.2.4rc1
1.2.5rc1
Fixed in
1.2.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.4rc1
pre
1 CVE
CVE-2026-34824
PYSEC-2026-2204
GHSA-3jr7-6hqp-x679
Apr 03, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework. This issue has been patched in version 1.2.5. Affected versions
1.2.3
1.2.4rc1
1.2.5rc1
Fixed in
1.2.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.3
patch
1 CVE
CVE-2026-34824
PYSEC-2026-2204
GHSA-3jr7-6hqp-x679
Apr 03, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthenticated attacker can send a rapid succession of WebSocket messages, forcing the server to spawn an unbounded number of operating system threads. This leads to thread exhaustion and Out of Memory (OOM) errors, causing a complete Denial of Service (DoS) for any application built on the framework. This issue has been patched in version 1.2.5. Affected versions
1.2.3
1.2.4rc1
1.2.5rc1
Fixed in
1.2.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.2
patch
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.2rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.1rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1
patch
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1rc3
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1rc2
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.1rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.1rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0rc2
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.2rc1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.2b2
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.2b1
pre
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.1
patch
2 CVEs
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.1rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.0
minor
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.13.0
minor
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.13.0rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.10rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.10b3
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.10b2
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.10b1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.9
patch
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.9rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.8
patch
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.8rc1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.8b1
pre
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.7
patch
3 CVEs
CVE-2025-30358
PYSEC-2026-1624
GHSA-f3mf-hm6v-jfhh
Jul 07, 2026
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
8.1
/ 10
High
Network
Low
Low
None
Unchanged
None
High
High
From @jackfromeast and @superboy-zjc: We have identified a class pollution vulnerability in Mesop (<= 0.14.0) application that allows attackers to overwrite global variables and class attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of service (DoS) attack against the server. Additionally, it could also result in other severe consequences given the application's implementation, such as identity confusion, where an attacker could impersonate an assistant or system role within conversations. This impersonation could potentially enable jailbreak attacks when interacting with large language models (LLMs). Just like the Javascript's prototype pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or control-flow of the application at runtime and lead to severe consequnces like RCE when gadgets are available. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 59 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
Fixed in
0.14.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-33057
PYSEC-2026-412
GHSA-gjgx-rvqr-6w6v
Jun 29, 2026
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryAn explicit web endpoint inside the DetailsThe AI codebase package includes a lightweight debugging Flask server inside
PoC
ImpactThis presents trivial severity for systems publicly exposed or lacking strictly verified boundary firewalls due to absolute unauthenticated command injection privileges targeting the direct execution interpreter running this service sandbox. Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33054
PYSEC-2026-411
GHSA-8qvf-mr4w-9x2c
Jun 29, 2026
Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryA Path Traversal vulnerability allows any user (or attacker) supplying an untrusted DetailsWhen the framework is configured to use the disk-based session backend (
Python's standard library natively resolves OS traversal semantics allowing full escape from the PoCAn attacker can utilize Python to craft and send a malicious Protobuf payload to the
ImpactThis vulnerability heavily exposes systems hosted utilizing Affected versions
0.0.1
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.11.0
0.11.0rc0
0.11.1
0.12.0
0.12.0rc0
0.12.1
0.12.10b1
+ 80 more Show less
0.12.10b2
0.12.10b3
0.12.10rc1
0.12.1rc0
0.12.2
0.12.3
0.12.3rc0
0.12.4
0.12.4rc0
0.12.5
0.12.5b1
0.12.5rc1
0.12.6
0.12.6rc1
0.12.7
0.12.7b1
0.12.7rc1
0.12.8
0.12.8b1
0.12.8rc1
0.12.9
0.12.9rc1
0.13.0
0.13.0rc1
0.14.0
0.14.1
0.14.1rc1
0.14.2b1
0.14.2b2
0.14.2rc1
0.14rc1
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.7.0
0.7.1
0.7.2
0.8.0
0.8.0rc0
0.9.0
0.9.0rc1
0.9.1
0.9.1rc1
0.9.2
0.9.2rc1
0.9.3
0.9.3rc0
0.9.4
0.9.4rc0
0.9.5
0.9.5rc0
1.0.0
1.0.0rc1
1.0.0rc2
1.0.1
1.0.1rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.1.1rc2
1.1.1rc3
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
Fixed in
1.2.3
References
Updated Jul 13, 2026 · Source: OSV.dev |