THREAT OPS › Threat News › [GHSA] GHSA-9w56-46f6-3qhx (medium) — asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
[GHSA] GHSA-9w56-46f6-3qhx (medium) — asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
GHSA-9w56-46f6-3qhx Severity: medium CVE: None
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
### Summary With its default configuration (numpy enabled, `import` disabled), asteval's `Interpreter` lets an attacker-controlled expression obtain a raw **arbitrary process-memory read and write** primitive, without using `import`, any `__dun
Indicators of compromise
- 16b67c5f9b5339a7e2bdc91423ff09e3md5
- CVE-2025-24359cve
Original source: https://github.com/advisories/GHSA-9w56-46f6-3qhx