CVE-2020-13388: Python Jw.util

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.

Affected products

  • Python Jw.util: before 2.3 (fixed in 2.3)

Published 2020-05-22. Last modified 2026-06-17.