CVE-2020-13388: Python Jw.util
Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.
Affected products
- Python Jw.util: before 2.3 (fixed in 2.3)
Published 2020-05-22. Last modified 2026-06-17.