CVE-2026-81096
Unauthenticated sandbox escape via dunder attribute injection in Python executor.
- CVSS 9.3
- 94
- Authentication, Authorization, and Session Management
- Remote
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup builtins available and did not stop a dunder attribute reached through a string lookup or through a module already permitted, so a caller could walk from a literal's class to its base and enumerate subclasses to obtain a reference to the process and subprocess modules. A per-call argument also let the caller widen the import allow-list before the inspection ran. The HTTP and MCP servers in http_api_server.py and smcp_server.py bound to every interface with debugging enabled and no authentication, so any caller able to reach the port executed code as the server process. Version 1.3.0 adds bearer-token authentication, defaults the bind address to loopback, and hardens the attribute checks.
- CWE
- 94
- CVSS base score
- 9.3
- Published
- 2026-08-27
- OWASP
- A01 Broken Access Control
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Authentication, Authorization, and Session Management
- Subcategory
- Insecure Authentication Mechanisms
- Accessibility scope
- Remote
- Impact
- Arbitrary Code Execution
- Affected component
- http_api_server.py
- Fixed by upgrading
- Yes
Solution
Upgrade to version 1.3.0, which adds authentication, binds to localhost by default, and hardens the attribute checks.
Vulnerable code sample
import ast
def execute_user_code(source: str, allow_imports: list = None):
# VULNERABLE: unsafe attribute access via string lookup
denied = {'__subclasses__', '__bases__', '__globals__', '__code__'}
tree = ast.parse(source, mode='exec')
for node in ast.walk(tree):
if isinstance(node, ast.Attribute):
attr = node.attr
if attr in denied:
raise ValueError("Denied attribute")
# allow_imports may widen import allow‑list before inspection
if allow_imports:
globals().update({mod: __import__(mod) for mod in allow_imports})
exec(source, {'__builtins__': {}}, {})Patched code sample
import ast
def execute_user_code(source: str, allow_imports: list = None):
# FIX: block dunder attributes before exec
denied = {'__subclasses__', '__bases__', '__globals__', '__code__'}
tree = ast.parse(source, mode='exec')
for node in ast.walk(tree):
if isinstance(node, ast.Attribute):
attr = node.attr
if attr.startswith('__') and attr.endswith('__') or attr in denied:
raise ValueError("Denied attribute")
if allow_imports:
# restrict imports to a safe whitelist
safe = {'json', 'math'}
for mod in allow_imports:
if mod not in safe:
raise ValueError("Import not allowed")
globals().update({mod: __import__(mod) for mod in allow_imports})
exec(source, {'__builtins__': {}}, {})Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202681096,
title = {{Unauthenticated sandbox escape via dunder attribute injection in Python executor.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-81096},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-81096/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
