Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjw9-4gw8-4rqx

Опубликовано: 19 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.9

Описание

Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution

Impact:

An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the InMemoryVectorStore filter functionality.

Patches:

The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.

Workarounds:

Avoid using InMemoryVectorStore for production scenarios.

References:

Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions

Пакеты

Наименование

semantic-kernel

pip
Затронутые версииВерсия исправления

< 1.39.4

1.39.4

EPSS

Процентиль: 25%
0.00089
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
около 1 месяца назад

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.

CVSS3: 9.9
msrc
15 дней назад

GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable

EPSS

Процентиль: 25%
0.00089
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94