Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Python" — 15 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 4 horas
[CVE-2026-108263] Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the…
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the docu…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107779] Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentica…
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor ho…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107377] datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.8…
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107295] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools wi…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107286] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream terminat…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-62176] PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generat…
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Ver…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-107204] LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows re…
LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the injected FastAPI app object, bypassing the guarded __import__, to import os and run operating system commands as the LMCache process.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-106558] Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, t…
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105812] Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore St…
Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated Python source without safe literal encoding. To remediate this issue, users s…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106441] Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, …
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or facto…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105782] Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, Refe…
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler pro…
M Alto vulnerabilidad
Hace 4 días
Papermerge 3.5.3: Ejecución remota de código mediante traversal de directorios
Papermerge versión 3.5.3 permite a usuarios estándar ejecutar código remoto explotando traversal de directorios en el endpoint /api/documents/upload. Un atacante puede escribir archivos Python .pth en site-packages que se ejecutan al reiniciar el intérprete, comprometiendo servidores de gestión documental en empresas LATAM. La vulnerabilidad afecta principalmente a organizaciones que confían en Papermerge para procesamiento de documentos sensibles.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104851] fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 …
fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in _process_references1._render_jinja, _process_templates, and _process_gen in fsspec/implementations/reference.py.…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-104020] Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote una…
Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-15911] Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obt…
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.