CVE-2018-8097: Python-Eve Eve

Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.

io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

Affected products

Published 2018-03-14. Last modified 2026-06-17.