CVE-2026-26030

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.9 EPSS 0.0007 Score 29.74

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2026-26030Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-26030Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2026-26030API EPSS dla CVE
security-advisories@github.comhttps://github.com/microsoft/semantic-kernel/pull/13505Issue Tracking, Patch
security-advisories@github.comhttps://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4Release Notes
security-advisories@github.comhttps://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqxPatch, Vendor Advisory