Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74896: openssl_encrypt before 1.4.0 can run unauthorized commands

CVE-2026-74896 · published 1 month ago
Summary

The jahlives/openssl_encrypt package, when it is older than version 1.4.0, does not properly block special code tricks that let a plugin break out of its safe area. This can let an attacker run any command on the server. Update to version 1.4.0 or newer to close the gap.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74896 · MITRE
Track software like this
Free during beta