Repository navigation
CVE-2025-50817 #650
Description
Activity
Relates to: #268
Reacted by Dan WReacted by Jason Fried@edschofield We got below dependabot for future package. When can we expect this to be solved. TIA

This CVE is beyond ridiculous. High severity is laughable. It boils down to "If you have access to my code you can execute arbitrary code".
testis in the standard lib, the standard lib has many modules and any of them could be "exploited" in this exact way. The only ones safe are builtins modules like "sys".If this is an expliot, then every piece of python code ever written that imports from the stdlib in any capacity is also exploited. Basic python import semantics is not a CVE. The exploit wouldn't even be in this project it would be in cpython itself. The only problem that project is active and everyone would realize how insane the CVE was and it would get redacted
Reacted by Kishor, Vlad the Lad, AJ Alon, filak, Michael Schlenker, Malakai Spann and haibeeyEven an LLM can easily shred this CVE - https://github.com/proxy/gist.github.com/fried/d2108a4932f3a22712dfc04598b5b8ce
Its a common issue, not a CVE - https://python-notes.curiousefficiency.org/en/latest/python_concepts/import_traps.html#the-name-shadowing-traphttps://docs.python.org/3/reference/import.html
https://docs.python.org/3/reference/import.html#searching
https://docs.python.org/3/library/sys_path_init.html
https://docs.python.org/3/library/test.htmlReacted by Kishor, Vlad the Lad and Brandon BaileyThanks @fried for sharing context.
I have requested this CVE to be rejected via MITRE CVE Request web form (CVE Request 1919432 for Update Published CVE) and linked both the standard Python documentation and this discussion.
Reacted by Kishor, Jason Fried, Vlad the Lad, Daniel Rice, Dmitrii Azarenko, Adrian, ash, AJ Alon, Ben Moss, filak and 1 more- added 3 commits that reference this issue
on Sep 12, 2025 Any updates to the CVE update request, @iamleot ?
@MindaugasBernatavicius no, I have not received any updates.
Reacted by M1ndas and Ron AlexssenHello, JFTR CVE-2025-50817 was marked as Disputed.
Reacted by M1ndas
Trivy scanner is now detecting future as having a High severity CVE
https://avd.aquasec.com/nvd/2025/cve-2025-50817/
Will this be addressed in an update to this module?