CVE-2026-93421: falha de média gravidade em mesop-dev mesop
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.4%
probabilidade de exploração
0.4%top 67% das CVEs
exploração observada
nãonenhuma fonte reporta
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report handler in mesop/server/static_file_serving.py, which prints them to standard output without neutralizing terminal control sequences. When an operator views the resulting logs in an ANSI-capable terminal, injected ANSI or VT100 sequences can clear or reposition the display, hide text, or present forged messages, reducing the integrity of monitoring and incident-response output. This issue is fixed in version 1.3.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Produtos afetados
mesop-dev · mesopCVEs relacionadas — mesop-dev mesop
No mesmo produto, das mais perigosas para as menos.
CVE-2026-33057CRITICALMesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-pyEPSS 4.1%CVE-2025-30358HIGHMesop Class Pollution vulnerability leads to DoS and Jailbreak attacksEPSS 0.7%CVE-2026-33054CRITICALMesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/DeletionEPSS 0.7%CVE-2026-34824HIGHMesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of ServiceEPSS 0.7%CVE-2026-77357HIGHMesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the serverEPSS 0.5%