Description
ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), while run() and eval() in asteval/asteval.py catch Exception rather than these non-Exception BaseException subclasses. When an attacker-controlled expression raises one of these classes, on_raise() passes the class to raise_exception(), and the resulting exception bypasses the interpreter's safety handlers and propagates into the calling application. A consuming service that evaluates untrusted expressions can therefore be terminated or have signal and cleanup handling disrupted, causing denial of service. The separately documented read-only open() capability is not part of this vulnerability. This issue is fixed in version 1.0.9.
Published: 2026-09-14
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unhandled BaseException subclasses
Action: Patch
AI Analysis

Impact

ASTEVAL evaluates Python expressions and statements. Before version 1.0.9, the module exposes BaseException subclasses—including SystemExit, KeyboardInterrupt, and GeneratorExit—to code evaluated by asteval.Interpreter.eval() because FROM_PY in asteval/astutils.py makes them available. The interpreter’s run() and eval() functions catch only Exception and do not intercept these BaseException subclasses. Consequently, if an attacker submits an expression that raises one of these classes, the on_raise() handler forwards the class to raise_exception(), allowing the exception to bypass the interpreter’s safety checks and propagate into the hosting application. This enables an untrusted expression to terminate the service or disrupt signal and cleanup handling, effectively causing a denial of service. The vulnerability is fixed in version 1.0.9.

Affected Systems

The vulnerability affects the lmfit:asteval package. Versions before 1.0.9 are vulnerable; the issue is fixed in 1.0.9 and later releases. Any system that imports asteval.Interpreter and evaluates expressions supplied by an untrusted source is at risk.

Risk and Exploitability

Based on the description, it is inferred that the attacker would submit a Python expression designed to raise a BaseException subclass such as SystemExit; this forms the likely attack vector. The moderate severity, and the EPSS score of < 1% indicates a very low likelihood of recent public exploitation. The vulnerability is not listed in the CISA KEV catalog a Python expression that raises a BaseException subclass such as SystemExit. Because the interpreter will not catch these subclasses, the exception propagates to the host application, potentially terminating it or causing unwanted shutdown behavior. The risk exists in any context where untrusted evaluation occurs, and the impact is denial of service rather than data compromise.

Generated by OpenCVE AI on September 20, 2026 at 22:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade lmfit:asteval to version 1.0.9 or later, which removes exposure of BaseException subclasses.
  • Run asteval in a separate, isolated processExit or similar interruption only terminates the child process, not the main service.
  • If using asteval is unavoidable expressions; instead use a dedicated safe evaluation library or implement strict input validation before invoking asteval.

Generated by OpenCVE AI on September 20, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-89v8-rhwq-hf77 asteval has a Sandbox Escape via BaseException Subclasses
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lmfit
Lmfit asteval
Vendors & Products Lmfit
Lmfit asteval

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), while run() and eval() in asteval/asteval.py catch Exception rather than these non-Exception BaseException subclasses. When an attacker-controlled expression raises one of these classes, on_raise() passes the class to raise_exception(), and the resulting exception bypasses the interpreter's safety handlers and propagates into the calling application. A consuming service that evaluates untrusted expressions can therefore be terminated or have signal and cleanup handling disrupted, causing denial of service. The separately documented read-only open() capability is not part of this vulnerability. This issue is fixed in version 1.0.9.
Title ASTEVAL: Sandbox Escape via BaseException Subclasses
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:17:50.777Z

Reserved: 2026-06-16T16:44:00.624Z

Link: CVE-2026-55244

cve-icon Vulnrichment

Updated: 2026-09-16T16:17:44.148Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:47.640

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses