CVE-2018-8097: Python-Eve Eve
Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.
io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
Affected products
- Python-Eve Eve: before 0.7.5 (fixed in 0.7.5)
Published 2018-03-14. Last modified 2026-06-17.