mesop
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mesoppage 1 of 1
- CVE-2024-45601HIGHCVSS 7.5EG 7.5fixed in 0.12.42024-09-18
vulnerable: 0.10.0 ... 0.9.5rc0 (26 versions)
Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could potentially allow unauthorized access to files on the server hosting the Mesop application. The…
- CVE-2025-30358HIGHCVSS 8.1EG 8.1fixed in 0.14.12025-03-27
vulnerable: 0.0.1 ... 0.9.5rc0 (71 versions)
Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and class attributes in certain Mesop modules…
- CVE-2026-33054CRITICALCVSS 9.8EG 9.8fixed in 1.2.32026-03-20
vulnerable: 0.0.1 ... 1.2.2rc1 (92 versions)
Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbi…
- CVE-2026-33057CRITICALCVSS 9.8EG 9.8fixed in 1.2.32026-03-20
vulnerable: 0.0.1 ... 1.2.2rc1 (92 versions)
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings uncondition…
- CVE-2026-34824HIGHCVSS 7.5EG 7.5fixed in 1.2.52026-04-03
vulnerable: 1.2.3, 1.2.4rc1, 1.2.5rc1
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resource consumption vulnerability exists in the WebSocket implementation of the Mesop framework.…
- CVE-2026-93421MEDIUMCVSS 5.3EG 5.3fixed in 1.3.42026-09-23
vulnerable: 0.0.1 ... 1.3.3 (104 versions)
Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report h…
Check whether mesop is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mesop CVEs against the assets you own.
Book a Demo →