CVE Feed

    Dashboard / CVE / CVE-2026-47103

    CVE-2026-47103

    Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chain ending in Python's built-in eval() without sandboxing, enabling arbitrary code execution in the context of the hosting process.

    Published:Jun 17, 2026
    Last Modified:Aug 28, 2026
    EPS:Jun 17, 2026
    EPSS Score:0.01348
    CVSS Score:9.8

    Affected Products

    Vendor
    Fgmacedo
    Product
    Python-statemachine
    Vendor
    Fgmacedo
    Product
    Python Statemachine

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High