High severity8.4NVD Advisory· Published Mar 18, 2024· Updated Jun 17, 2026
CVE-2023-41334
CVE-2023-41334
Description
Astropy is a project for astronomy in Python that fosters interoperability between Python astronomy packages. Version 5.3.2 of the Astropy core package is vulnerable to remote code execution due to improper input validation in the TranformGraph().to_dot_graph function. A malicious user can provide a command or a script file as a value to the savelayout argument, which will be placed as the first value in a list of arguments passed to subprocess.Popen. Although an error will be raised, the command or script will be executed successfully. Version 5.3.3 fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
astropyPyPI | < 5.3.3 | 5.3.3 |
Affected products
4- ghsa-coords2 versions
< 5.3.3+ 1 more
- (no CPE)range: < 5.3.3
- (no CPE)range: < 8.0.1-1.1
- astropy/astropyv5Range: = 5.3.2
Patches
Vulnerability mechanics
References
5- github.com/astropy/astropy/commit/22057d37b1313f5f5a9b5783df0a091d978dccb5nvdPatchWEB
- github.com/astropy/astropy/security/advisories/GHSA-h2x6-5jx5-46hfnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-h2x6-5jx5-46hfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-41334ghsaADVISORY
- github.com/astropy/astropy/blob/9b97d98802ee4f5350a62b681c35d8687ee81d91/astropy/coordinates/transformations.pynvdProductWEB
News mentions
0No linked articles in our index yet.