PyPi: Mesop

CVE-2025-30358

Safety vulnerability ID: 76171

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 27, 2025 Updated at Apr 01, 2025
Scan your Python projects for vulnerabilities →

Advisory

Affected versions of the Mesop Python package (≤ 0.14.0) are vulnerable to a class pollution vulnerability. An attacker may exploit improper handling of double-underscore properties in dataclass utilities to overwrite critical global and class attributes, potentially triggering denial-of-service (DoS) and identity impersonation attacks. The vulnerability is exploitable via remote JSON input and affects functions such as update_dataclass_from_json. Remediation involves upgrading to Mesop version 0.14.1 or later. Note: This issue is specific to Python frameworks and is rated CVSS 8.1 (CWE-915), reflecting independent assessments beyond standard Mitre/NVD metrics.

Affected package

mesop

Latest version: 1.0.1

Build UIs in Python

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application