What is CVE-2026-67195?
A remote code execution vulnerability in Perspective 5.0.0 allows unauthenticated attackers to execute arbitrary OS commands via crafted expression strings sent to the PolarsVirtualServer backend. This occurs because the application passes user-supplied input directly to Python's eval() function. Immediate update to the latest version is strongly advised.
Azərbaycanca: Perspective 5.0.0 məhsulunda autentifikasiya olunmamış hücumçulara PolarsVirtualServer backend vasitəsilə əməliyyat sistemi əmrlərini yerinə yetirməyə imkan verən uzaqdan kod icrası (RCE) zəifliyi aşkarlanıb. Bu, tətbiqin istifadəçi tərəfindən ötürülən ifadələri birbaşa Python-un eval() funksiyasına ötürməsi səbəbindən baş verir. Təcili olaraq Perspective-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of Perspective is affected by CVE-2026-67195?
Perspective version 5.0.0 is affected by this remote code execution (RCE) vulnerability.
What is the root cause of CVE-2026-67195?
The vulnerability occurs because the application passes user-supplied input directly to Python's eval() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.