A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.
History

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Python
Python python
Vendors & Products Python
Python python

Fri, 15 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Fri, 15 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
Title pypi-future: Python future unintended import
Weaknesses CWE-94
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

threat_severity

Important


Thu, 14 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-08-15T16:37:04.248Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50817

cve-icon Vulnrichment

Updated: 2025-08-15T16:36:58.332Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T17:15:40.947

Modified: 2025-08-15T17:15:32.020

Link: CVE-2025-50817

cve-icon Redhat

Severity : Important

Publid Date: 2025-08-14T00:00:00Z

Links: CVE-2025-50817 - Bugzilla