GHSA-v4jc-pm6r-3vj8
CRITICALCVE-2026-47103python-statemachine 3.1.2 evaluates <data expr="..."> attributes in SCXML documents using Python's eval(). Any application that passes attacker-controlled SCXML content to SCXMLProcessor is vulnerable to arbitrary code execution in the context of the hosting process.
- Affected
- >= 3.0.0, < 3.2.0
- Fixed in
- 3.2.0
- Weakness
- CWE-95
- Published
- 2026-06-18
- Source
- github