peter bassill · operator
$ cve CVE-2009-0367 JSON

CVE-2009-0367 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 10.9% (pctl 96)

Patch early

A public exploit exists.

Description

The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS10.94% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-03-05
Last modified2026-06-16

Affected (1)

VendorProduct
wesnothwesnoth

Public exploits

SourceTitleDate
exploit-dbWesnoth 1.x - PythonAI Remote Code Execution2009-02-25

References

→ the Explorer  ·  watch your stack  ·  NVD