THREAT OPS › Threat News › [NVD] CVE-2026-47103 (CRITICAL 9.8) — Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes at
[NVD] CVE-2026-47103 (CRITICAL 9.8) — Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes at
CVE-2026-47103 CVSS: 9.8 CRITICAL Published: 2026-06-17T15:16:58.460
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a cal
Indicators of compromise
- CVE-2026-47103cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47103