THREAT OPS › Threat News › [GHSA] GHSA-jrw6-7x4q-w25j (critical) — senaite.core Vulnerable to Eval Injection and Missing Authorization
[GHSA] GHSA-jrw6-7x4q-w25j (critical) — senaite.core Vulnerable to Eval Injection and Missing Authorization
GHSA-jrw6-7x4q-w25j Severity: critical CVE: CVE-2026-54569
senaite.core Vulnerable to Eval Injection and Missing Authorization
### Summary
An unauthenticated remote code execution vulnerability in the SENAITE JSON API allows any network-reachable attacker to execute arbitrary Python on the Zope worker process via a two-request anonymous chain. The `/@@API/update` route is reachable to anonymous
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 8dbc161fa9f74aa4ad6e76eb1934518amd5
- CVE-2026-54569cve
- http://listener:8000url
- https://machinespirits.comurl
Original source: https://github.com/advisories/GHSA-jrw6-7x4q-w25j