High severity8.8OSV Advisory· Published Aug 17, 2026· Updated Sep 1, 2026
CVE-2026-74883
CVE-2026-74883
Description
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <1.4.0
Patches
Vulnerability mechanics
References
2- github.com/jahlives/openssl_encrypt/security/advisories/GHSA-mcjj-qw7m-j3cpnvdExploitMitigationVendor Advisory
- www.vulncheck.com/advisories/openssl-encrypt-before-sandbox-bypass-via-pathlib-and-ionvdThird Party Advisory
News mentions
1- Jahlives openssl_encrypt: 25 Critical Flaws Including Auth Bypass and Sandbox Escapes Disclosed TogetherVypr Intelligence · Aug 17, 2026