GHSA-q27q-98j4-9pfv: qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
Summary
The qwed package (version 5.1.1) has a critical vulnerability where user-supplied mathematical expressions are passed directly to SymPy's `parse_expr()` function without restrictions. Since `parse_expr()` internally uses Python's `eval()` (a function that runs arbitrary code), any authenticated user can execute malicious Python code on the server, leading to complete compromise. An attacker only needs to create a free account through the signup endpoint to exploit this.
Vulnerability Details
EPSS: 0.0%
Yes
August 25, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-q27q-98j4-9pfv
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%