VYPR

Tooluniverse

by Mims Harvard

CVEs (1)

  • CVE-2026-81096CriAug 27, 2026
    risk 0.58cvss 10.0epss

    ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and…