{"id":"CVE-2023-33733","aliases":["GHSA-9q9m-c65c-37pq","PYSEC-2026-1871"],"url":"https://o3.security/vulnerability/CVE-2023-33733","summary":"Reportlab vulnerable to remote code execution","details":"Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.","published":"2023-06-05T16:15:09.550Z","modified":"2026-07-07T17:56:33.342345330Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":4,"affectedPackages":[{"ecosystem":"PyPI","name":"reportlab","fixedVersion":"3.6.13"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36WOY22ECJCPOXHVTNCHEWOQLL7JSWP4/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ALE727IRACYBTTOFIFG57RS4OA2SHIJ/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/10/msg00008.html"},{"type":"EVIDENCE","url":"https://github.com/c53elyas/CVE-2023-33733"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:33.342345330Z"}}