High severity8.8NVD Advisory· Published Aug 17, 2026· Updated Aug 17, 2026
CVE-2026-74883
CVE-2026-74883
Description
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
Affected products
1- Range: <1.4.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.