{"id":"CVE-2024-27758","aliases":["GHSA-h5cg-53g7-gqjw","PYSEC-2024-44"],"url":"https://o3.security/vulnerability/CVE-2024-27758","summary":"RPyC's missing security check results in code execution when using numpy.array on the server-side.","details":"In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.","published":"2024-03-12T00:00:00Z","modified":"2026-07-15T01:49:02.725943894Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"rpyc","fixedVersion":"6.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://gist.github.com/renbou/957f70d27470982994f12a1d70153d09"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27758.json"},{"type":"ADVISORY","url":"https://github.com/tomerfiliba-org/rpyc/security/advisories/GHSA-h5cg-53g7-gqjw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27758"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:02.725943894Z"}}