semantic-kernel
Integrate cutting-edge LLM technology quickly and easily into your apps
Activity
- Latest release
- 1mo ago
- Total releases
- 137
- Cadence
- ~8 days
- Last 12 months
- 17
Reach
- Stars
- 28.4k
Details
- License
- MIT
- First release
- Mar 17, 2023
| Version | Released | |
|---|---|---|
1.44.1
patch
|
1.44.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.44.0
minor
|
1.44.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.43.1
patch
|
1.43.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.43.0
minor
|
1.43.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.42.0
minor
|
1.42.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.41.3
patch
|
1.41.3
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.41.2
patch
|
1.41.2
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.41.1
patch
|
1.41.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.41.0
minor
|
1.41.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.40.0
minor
|
1.40.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.39.4
patch
|
1.39.4
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
1.39.3
patch
1 CVE
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.39.3
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
1.39.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.39.2
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
1.39.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.39.1
patch
Dependencies (63)
+ 55 more
Changelog
Compare changes
|
|
1.39.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.39.0
minor
Dependencies (62)
+ 54 more
Changelog
Compare changes
|
|
1.38.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.38.0
minor
Dependencies (62)
+ 54 more
Changelog
Compare changes
|
|
1.37.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.37.1
patch
Dependencies (62)
+ 54 more
Changelog
Compare changes
|
|
1.37.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.37.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.36.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.36.2
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.36.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.36.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.36.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.36.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.35.3
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.35.3
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.35.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.35.2
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.35.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.35.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.35.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.35.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.34.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.34.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.33.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.33.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.32.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.32.2
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.32.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.32.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.32.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.32.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.31.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.31.0
minor
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
1.30.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.30.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
1.29.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.29.0
minor
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.28.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.28.1
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.28.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.28.0
minor
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.27.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.27.2
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.27.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.27.1
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.27.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.27.0
minor
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
1.26.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.26.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
1.26.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.26.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
1.25.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.25.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
1.24.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.24.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
1.24.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.24.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
1.23.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.23.1
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
1.23.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.23.0
minor
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
1.22.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.22.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
1.22.0
minor
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.22.0
minor
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
1.21.3
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.21.3
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
1.21.2
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.21.2
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
1.21.1
patch
2 CVEs
CVE-2026-25592
PYSEC-2026-531
GHSA-2ww3-72rp-wpp4
Jun 29, 2026
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
ImpactWhat kind of vulnerability is it? Who is impacted?
An Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the PatchesHas the problem been patched? What versions should users upgrade to? The problem has been fixed in Microsoft.SemanticKernel.Plugins.Core version 1.71.0. Users should upgrade to version 1.71.0 or higher. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading?
Users can create a Function Invocation Filter which checks the arguments being passed to any calls to ReferencesAre there any links users can visit to find out more? Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 113 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.3
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-26030
GHSA-xjw9-4gw8-4rqx
PYSEC-2026-163
Feb 19, 2026
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Impact:An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the Patches:The problem has been fixed in python-1.39.4. Users should upgrade this version or higher. Workarounds:Avoid using References:Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions Affected versions
0.0.1.dev0
0.1.0.dev0
0.2.0.dev0
0.2.1.dev0
0.2.2.dev0
0.2.3.dev0
0.2.4.dev0
0.2.5.dev0
0.2.6.dev0
0.2.7.dev0
0.2.8.dev0
0.2.9.dev0
+ 114 more Show less
0.3.0.dev0
0.3.1.dev0
0.3.10.dev0
0.3.11.dev0
0.3.12.dev0
0.3.13.dev0
0.3.14.dev0
0.3.15.dev0
0.3.2.dev0
0.3.3.dev0
0.3.4.dev0
0.3.5.dev0
0.3.6.dev0
0.3.7.dev0
0.3.8.dev0
0.3.9.dev0
0.4.0.dev0
0.4.1.dev0
0.4.2.dev0
0.4.3.dev0
0.4.4.dev0
0.4.5.dev0
0.4.6.dev0
0.4.7.dev0
0.5.0.dev0
0.5.1.dev0
0.9.0b1
0.9.1b1
0.9.2b1
0.9.3b1
0.9.4b1
0.9.5b1
0.9.6b1
0.9.7b1
0.9.8b1
0.9.9b1
1.0.0
1.0.0rc1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.10.0
1.10.1
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.2.0
1.20.0
1.21.0
1.21.1
1.21.2
1.21.3
1.22.0
1.22.1
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.29.0
1.3.0
1.30.0
1.31.0
1.32.0
1.32.1
1.32.2
1.33.0
1.34.0
1.35.0
1.35.1
1.35.2
1.35.3
1.36.0
1.36.1
1.36.2
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.39.2
1.39.3
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
Fixed in
1.39.4
References
Updated Jun 08, 2026 · Source: OSV.dev |
1.21.1
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|