Skip to main content

Vendor/product archive

dabeaz / ply CVEs

Beta · best-effort

1 CVEs tagged to dabeaz / ply1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-56005

Published Jan 20, 2026

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This param…

CVSS 9.8 · Critical
evidence mentions
13
Buzz score
54.4
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1