CVE-2026-93421
- EPSS 0.4%
- Veröffentlicht 23.09.2026 18:59:52
- Zuletzt bearbeitet 30.09.2026 17:32:07
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in m...
CVE-2026-77357
- EPSS 0.3%
- Veröffentlicht 25.08.2026 20:40:39
- Zuletzt bearbeitet 09.09.2026 21:09:13
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, allowing an un...
CVE-2026-34824
- EPSS 0.72%
- Veröffentlicht 03.04.2026 22:41:34
- Zuletzt bearbeitet 24.07.2026 22:10:00
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework. An unauthe...
CVE-2026-33057
- EPSS 5.29%
- Veröffentlicht 20.03.2026 07:16:59
- Zuletzt bearbeitet 24.03.2026 16:04:15
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings unconditionally withou...
CVE-2026-33054
- EPSS 0.71%
- Veröffentlicht 20.03.2026 07:16:13
- Zuletzt bearbeitet 24.03.2026 16:29:12
Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily tar...