QID 997431
Date Published: 2024-02-22
QID 997431: Python (Pip) Security Update for pymatgen (GHSA-vgv8-5cpj-qj2f)
A critical security vulnerability exists in the JonesFaithfulTransformation.from_transformation_str() method within the pymatgen library. This method insecurely utilizes eval() for processing input, enabling execution of arbitrary code when parsing untrusted input. This can be exploited when parsing a maliciously-created CIF file.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vgv8-5cpj-qj2f for updates and patch information.
Vendor References
- GHSA-vgv8-5cpj-qj2f -
github.com/advisories/GHSA-vgv8-5cpj-qj2f
CVEs related to QID 997431
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vgv8-5cpj-qj2f | pymatgen |
|