Impact
Perspective 5.0.0 incorporates a Python eval() call that removes only the built‑in namespace without sanitizing user input. An unauthenticated attacker can submit a crafted expression within a Protobuf request that traverses Python object attributes to reach subprocess.Popen, resulting in execution of arbitrary operating‑system commands. This flaw grants full code‑execution privileges on the host process, exposing the system to data theft, service disruption, or further lateral movement.
Affected Systems
The vulnerability affects Perspective version 5.0.0, released by perspective‑dev:perspective. No other versions were confirmed under the CNA record. The flaw resides in the PolarsVirtualServer backend that processes client requests.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is unavailable, but the lack of external exploitation reports does not diminish the inherent risk of remote code execution. The flaw is not listed in the CISA KEV catalog. Attackers can abuse the flaw from any network location that can reach the Perspective service, without authentication or privilege escalation. The feasibility is high since the vulnerability requires only the ability to send a crafted request to the backend.
OpenCVE Enrichment