Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74886: openssl_encrypt before 1.4.0 allows malicious code execution
CVE-2026-74886 · published 1 month ago
Summary
The jahlives/openssl_encrypt library versions earlier than 1.4.0 can be tricked into loading dangerous code modules. An attacker could hide malicious instructions and cause the software to run arbitrary commands on your system. Upgrade to version 1.4.0 or later to close this gap.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Plugin Import Guard Bypass
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-9pgj-v69p-q... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-plugin-import-guard-... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74886... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74886 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta