
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33057 is a critical unauthenticated remote code execution (RCE) vulnerability in the Mesop Python UI framework, affecting all versions up to and including 1.2.2. The flaw resides in a debugging Flask server endpoint (/exec-py) within the ai/sandbox/wsgi_app.py module, which accepts and executes arbitrary base64-encoded Python code without any authentication or input validation. It was published on March 17, 2026, and patched in version 1.2.3. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Mesop Security Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerable ai/sandbox/wsgi_app.py file exposes a Flask route /exec-py that accepts HTTP POST requests containing a code parameter with base64-encoded Python source code. The server decodes the payload using base64.urlsafe_b64decode(), writes it to a file on the host filesystem, and then executes it via execute_module(module_path...) — all without any authentication check, input sanitization, or sandboxing. This testing/debugging infrastructure was inadvertently included in production-distributed packages, making it exploitable by any network-reachable attacker (GitHub Advisory, Mesop Security Advisory).
Successful exploitation grants an unauthenticated attacker full remote code execution on the host machine with the privileges of the running Mesop service process. This results in complete compromise of confidentiality (arbitrary file read, credential theft), integrity (file creation/modification/deletion, code tampering), and availability (service disruption or destruction). Attackers can establish persistent reverse shells, pivot to other internal systems, or exfiltrate sensitive data, making this vulnerability particularly dangerous for any internet-exposed deployment (GitHub Advisory, Feedly).
A public proof-of-concept (PoC) is included directly in the official security advisory, demonstrating exploitation via a single curl command with a base64-encoded Python payload. As of the time of disclosure, there is no confirmed evidence of active in-the-wild exploitation or known threat actor attribution. The EPSS score is approximately 12.9% (94th percentile), indicating a relatively elevated probability of exploitation. A Nuclei detection template was added to the ProjectDiscovery nuclei-templates repository, further lowering the barrier for automated scanning (GitHub Advisory, Nuclei Templates, Feedly).
import base64
payload = b'import os\nos.system(\'echo "pwned" > /tmp/pwned.txt\')'
print(base64.urlsafe_b64encode(payload).decode())/exec-py endpoint with no authentication required:curl -X POST http://<target_ip>:<port>/exec-py \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "code=aW1wb3J0IG9zCm9zLnN5c3RlbSgnZWNobyAicHduZWQgYnkgYXR0YWNrZXIiID4gL3RtcC9wd25lZC50eHQnKQ=="execute_module(), running the attacker's code with the service account's privileges./exec-py on the Mesop sandbox server port; outbound connections from the Mesop server process to unknown external IPs (potential reverse shell activity)./tmp/ or the application working directory written by the Mesop service account (e.g., /tmp/pwned.txt or temporary Python script files); unexpected scripts or binaries dropped by the service process./exec-py with a code parameter containing base64-encoded strings; error logs indicating Python module execution from unexpected paths./bin/bash, sh, curl, wget, python3) that are not part of normal application behavior; unexpected network connections initiated by the service process (GitHub Advisory, Feedly).The primary remediation is to upgrade Mesop to version 1.2.3 or later, which removes the entire ai/ package and its associated sandbox infrastructure (commit 825f559) (Patch Commit). If immediate patching is not possible, restrict network access to the sandbox server port via firewall rules to trusted internal networks only, and disable or remove the ai/sandbox/ module from any production deployment. Additionally, implement network-level monitoring for POST requests to /exec-py endpoints and consider isolating affected systems until the patch is applied (GitHub Advisory, Feedly).
The vulnerability was reported by researcher liyander and published by the Mesop maintainer richard-to on March 17, 2026. Coverage appeared on security news outlets including The Hacker Wire and Yazoul.net, which highlighted the trivial exploitability of the unauthenticated endpoint. Social media discussion was noted on Mastodon and Bluesky, and the vulnerability was picked up by automated CVE tracking feeds. Cloudflare also added WAF rules for this CVE in their scheduled WAF releases (The Hacker Wire, Yazoul Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."