Vulnerability Description
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chain ending in Python's built-in eval() without sandboxing, enabling arbitrary code execution in the context of the hosting process.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fgmacedo | Python Statemachine | >= 3.0.0, < 3.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/fgmacedo/python-statemachine/releases/tag/v3.2.0Release Notes
- https://github.com/fgmacedo/python-statemachine/security/advisories/GHSA-v4jc-pmExploitVendor Advisory
- https://www.vulncheck.com/advisories/python-statemachine-rce-via-scxml-eval-injeThird Party AdvisoryVDB Entry
- https://github.com/fgmacedo/python-statemachine/security/advisories/GHSA-v4jc-pmExploitVendor Advisory
FAQ
What is CVE-2026-47103?
CVE-2026-47103 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted...
How severe is CVE-2026-47103?
CVE-2026-47103 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-47103?
Check the references section above for vendor advisories and patch information. Affected products include: Fgmacedo Python Statemachine.