THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q27q-98j4-9pfv (high) — qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

[GHSA] GHSA-q27q-98j4-9pfv (high) — qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

highgithub_advisoriesPublished 2026-08-25

GHSA-q27q-98j4-9pfv Severity: high CVE: CVE-2026-55585

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

### Summary

The `qwed` package (version 5.1.1) passes attacker-controlled input directly to SymPy's `parse_expr()` function without a restricted namespace. Because `parse_expr()` internally calls Python's `eval()`, any authenticated tenant can execute arb

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q27q-98j4-9pfv