THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-9147 (HIGH 7.8) — uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting v

[NVD] CVE-2026-9147 (HIGH 7.8) — uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting v

lownvdPublished 2026-07-18

CVE-2026-9147 CVSS: 7.8 HIGH Published: 2026-07-18T13:17:06.273

uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier. An attacker who c

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9147