VAITP Dataset

← Back to the dataset

CVE-2026-81096

Unauthenticated sandbox escape via dunder attribute injection in Python executor.

  • CVSS 9.3
  • 94
  • Authentication, Authorization, and Session Management
  • Remote

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup builtins available and did not stop a dunder attribute reached through a string lookup or through a module already permitted, so a caller could walk from a literal's class to its base and enumerate subclasses to obtain a reference to the process and subprocess modules. A per-call argument also let the caller widen the import allow-list before the inspection ran. The HTTP and MCP servers in http_api_server.py and smcp_server.py bound to every interface with debugging enabled and no authentication, so any caller able to reach the port executed code as the server process. Version 1.3.0 adds bearer-token authentication, defaults the bind address to loopback, and hardens the attribute checks.

CWE
94
CVSS base score
9.3
Published
2026-08-27
OWASP
A01 Broken Access Control
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Authentication, Authorization, and Session Management
Subcategory
Insecure Authentication Mechanisms
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Affected component
http_api_server.py
Fixed by upgrading
Yes

Solution

Upgrade to version 1.3.0, which adds authentication, binds to localhost by default, and hardens the attribute checks.

Vulnerable code sample

import ast

def execute_user_code(source: str, allow_imports: list = None):
    # VULNERABLE: unsafe attribute access via string lookup
    denied = {'__subclasses__', '__bases__', '__globals__', '__code__'}
    tree = ast.parse(source, mode='exec')
    for node in ast.walk(tree):
        if isinstance(node, ast.Attribute):
            attr = node.attr
            if attr in denied:
                raise ValueError("Denied attribute")
    # allow_imports may widen import allow‑list before inspection
    if allow_imports:
        globals().update({mod: __import__(mod) for mod in allow_imports})
    exec(source, {'__builtins__': {}}, {})

Patched code sample

import ast

def execute_user_code(source: str, allow_imports: list = None):
    # FIX: block dunder attributes before exec
    denied = {'__subclasses__', '__bases__', '__globals__', '__code__'}
    tree = ast.parse(source, mode='exec')
    for node in ast.walk(tree):
        if isinstance(node, ast.Attribute):
            attr = node.attr
            if attr.startswith('__') and attr.endswith('__') or attr in denied:
                raise ValueError("Denied attribute")
    if allow_imports:
        # restrict imports to a safe whitelist
        safe = {'json', 'math'}
        for mod in allow_imports:
            if mod not in safe:
                raise ValueError("Import not allowed")
        globals().update({mod: __import__(mod) for mod in allow_imports})
    exec(source, {'__builtins__': {}}, {})

Payload

__VAITP_MODEL_REFUSED__

Cite this entry

@misc{vaitp:cve202681096,
  title        = {{Unauthenticated sandbox escape via dunder attribute injection in Python executor.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-81096},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-81096/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::