Описание
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the InMemoryVectorStore filter functionality. The problem has been fixed in version python-1.39.4. Users should upgrade this version or higher. As a workaround, avoid using InMemoryVectorStore for production scenarios.
Ссылки
- Issue TrackingPatch
- Release Notes
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.39.4 (исключая)
cpe:2.3:a:microsoft:semantic_kernel:*:*:*:*:*:python:*:*
EPSS
Процентиль: 25%
0.00089
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9.9
msrc
15 дней назад
GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
CVSS3: 9.9
github
около 1 месяца назад
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
EPSS
Процентиль: 25%
0.00089
Низкий
9.9 Critical
CVSS3
Дефекты
CWE-94