THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-47103 (CRITICAL 9.8) — Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes at

[NVD] CVE-2026-47103 (CRITICAL 9.8) — Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes at

lownvdPublished 2026-06-17

CVE-2026-47103 CVSS: 9.8 CRITICAL Published: 2026-06-17T15:16:58.460

Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a cal

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47103