CVE-2026-93421: fallo de gravedad media en mesop-dev mesop
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 67% de las CVE
explotación observada
noninguna fuente lo reporta
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Productos afectados
mesop-dev · mesopCVEs relacionadas — mesop-dev mesop
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-33057CRITICALMesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-pyEPSS 4.1%CVE-2025-30358HIGHMesop Class Pollution vulnerability leads to DoS and Jailbreak attacksEPSS 0.7%CVE-2026-33054CRITICALMesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/DeletionEPSS 0.7%CVE-2026-34824HIGHMesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of ServiceEPSS 0.7%CVE-2026-77357HIGHMesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the serverEPSS 0.5%