Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74886: openssl_encrypt before 1.4.0 allows malicious code execution

CVE-2026-74886 · published 1 month ago
Summary

The jahlives/openssl_encrypt library versions earlier than 1.4.0 can be tricked into loading dangerous code modules. An attacker could hide malicious instructions and cause the software to run arbitrary commands on your system. Upgrade to version 1.4.0 or later to close this gap.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Plugin Import Guard Bypass
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-184Incomplete List of Disallowed Inputs
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74886 · MITRE
Track software like this
Free during beta