{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/perspective/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-67195"},{"cvss":7.5,"id":"CVE-2026-67200"},{"cvss":7.5,"id":"CVE-2026-67198"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Perspective (5.0.0)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cve-2026-67195","perspective","denial-of-service","vulnerability","CVE-2026-67198"],"_cs_type":"advisory","_cs_vendors":["Perspective"],"content_html":"\u003cp\u003ePerspective version 5.0.0 contains a critical remote code execution vulnerability (CVE-2026-67195) located within its PolarsVirtualServer backend component. The vulnerability originates from the unsafe handling of client-supplied expression strings, which are passed directly to Python's eval() function. Although the application attempts to restrict the environment by clearing \u003cstrong\u003ebuiltins\u003c/strong\u003e, this mechanism is insufficient as it does not prevent object attribute traversal. An attacker can leverage this limitation to traverse the interpreter's loaded class hierarchy, eventually accessing subprocess.Popen to execute arbitrary operating system commands. This flaw is reachable by unauthenticated attackers who can deliver specially crafted TableValidateExprReq or TableMakeViewReq protobuf messages to the service. Given that Perspective is often deployed in data-intensive environments, successful exploitation allows an attacker to gain full control over the host process and the underlying system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in unauthenticated remote code execution with the privileges of the Perspective host process. This can lead to full system compromise, data exfiltration, or the deployment of further post-exploitation payloads. All instances of Perspective 5.0.0 are considered high-risk until patched.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all deployments of Perspective 5.0.0 in the environment and verify if they are internet-facing.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls to restrict access to the PolarsVirtualServer service to trusted management segments only.\u003c/li\u003e\n\u003cli\u003ePrioritize upgrading Perspective to a patched version once provided by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor server logs for incoming traffic containing protobuf serialization patterns associated with TableValidateExprReq or TableMakeViewReq types if application-level inspection is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T15:44:26Z","date_published":"2026-08-04T15:44:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-perspective-rce/","summary":"Perspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.","title":"Unauthenticated Remote Code Execution in Perspective 5.0.0","url":"https://feed.craftedsignal.io/briefs/2026-08-perspective-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Perspective","version":"https://jsonfeed.org/version/1.1"}