THREAT OPS › Threat News › [GHSA] GHSA-q27q-98j4-9pfv (high) — qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
[GHSA] GHSA-q27q-98j4-9pfv (high) — qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
GHSA-q27q-98j4-9pfv Severity: high CVE: CVE-2026-55585
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
### Summary
The `qwed` package (version 5.1.1) passes attacker-controlled input directly to SymPy's `parse_expr()` function without a restricted namespace. Because `parse_expr()` internally calls Python's `eval()`, any authenticated tenant can execute arb
Indicators of compromise
- CVE-2026-55585cve
- http://localhost`url
- http://127.0.0.1:8765/auth/signupurl
- http://127.0.0.1:8765/auth/api-keysurl
- http://127.0.0.1:8765/verify/mathurl
- http://{args.host}:{args.port}url
- 4.13.3.0ipv4
Original source: https://github.com/advisories/GHSA-q27q-98j4-9pfv