Impact
ASTEVAL evaluates Python expressions and statements. Before version 1.0.9, the module exposes BaseException subclasses—including SystemExit, KeyboardInterrupt, and GeneratorExit—to code evaluated by asteval.Interpreter.eval() because FROM_PY in asteval/astutils.py makes them available. The interpreter’s run() and eval() functions catch only Exception and do not intercept these BaseException subclasses. Consequently, if an attacker submits an expression that raises one of these classes, the on_raise() handler forwards the class to raise_exception(), allowing the exception to bypass the interpreter’s safety checks and propagate into the hosting application. This enables an untrusted expression to terminate the service or disrupt signal and cleanup handling, effectively causing a denial of service. The vulnerability is fixed in version 1.0.9.
Affected Systems
The vulnerability affects the lmfit:asteval package. Versions before 1.0.9 are vulnerable; the issue is fixed in 1.0.9 and later releases. Any system that imports asteval.Interpreter and evaluates expressions supplied by an untrusted source is at risk.
Risk and Exploitability
Based on the description, it is inferred that the attacker would submit a Python expression designed to raise a BaseException subclass such as SystemExit; this forms the likely attack vector. The moderate severity, and the EPSS score of < 1% indicates a very low likelihood of recent public exploitation. The vulnerability is not listed in the CISA KEV catalog a Python expression that raises a BaseException subclass such as SystemExit. Because the interpreter will not catch these subclasses, the exception propagates to the host application, potentially terminating it or causing unwanted shutdown behavior. The risk exists in any context where untrusted evaluation occurs, and the impact is denial of service rather than data compromise.
OpenCVE Enrichment
Github GHSA