Description
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5763-1 | pymatgen security update |
Github GHSA |
GHSA-vgv8-5cpj-qj2f | pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 05 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Materialsvirtuallab
Materialsvirtuallab pymatgen |
|
| CPEs | cpe:2.3:a:materialsvirtuallab:pymatgen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Materialsvirtuallab
Materialsvirtuallab pymatgen |
Mon, 19 Aug 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-19T07:47:59.282Z
Reserved: 2024-01-15T15:19:19.446Z
Link: CVE-2024-23346
Updated: 2024-08-19T07:47:59.282Z
Status : Analyzed
Published: 2024-02-21T17:15:09.377
Modified: 2025-02-05T22:10:07.683
Link: CVE-2024-23346
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA