HIGH 8.8 PyPI
CVE-2026-81698
PYSEC-2026-3776 · CVE-2026-81698 · GHSA-gw2m-mj6q-59hc
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.
Ready to move
Start Securing
Free, no credit card | First findings in minutes