Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74896: openssl_encrypt before 1.4.0 can run unauthorized commands
CVE-2026-74896 · published 1 month ago
Summary
The jahlives/openssl_encrypt package, when it is older than version 1.4.0, does not properly block special code tricks that let a plugin break out of its safe area. This can let an attacker run any command on the server. Update to version 1.4.0 or newer to close the gap.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74896... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74896 Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-sandbox-escape-via-d... Third Party Advisory
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-w7gr-9g4g-3... Mitigation Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta