Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.
History

Mon, 19 Aug 2024 08:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-21T16:13:25.498Z

Updated: 2024-08-19T07:47:59.282Z

Reserved: 2024-01-15T15:19:19.446Z

Link: CVE-2024-23346

cve-icon Vulnrichment

Updated: 2024-08-19T07:47:59.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-21T17:15:09.377

Modified: 2024-02-22T19:07:27.197

Link: CVE-2024-23346

cve-icon Redhat

No data.