A critical remote code execution vulnerability, tracked as CVE-2021-47952, affects the Python jsonpickle library through unsafe deserialization of untrusted JSON. In jsonpickle 2.0.0, applications that pass attacker-controlled data to jsonpickle.decode() can be compromised because the py/repr tag is processed by an internal repr-loading path that forwards input into Python's eval(), allowing arbitrary code execution with the privileges of the running process. The issue requires no authentication, special privileges, or user interaction beyond the target application decoding malicious input.
Public exploit details show the flaw can be triggered remotely with crafted serialized data containing a py/repr field, enabling execution of arbitrary Python commands and potentially system-level calls on both Windows and Linux. Earlier reporting said the behavior existed for backward compatibility across versions and initially lacked a patch, while later project changes reportedly removed reliance on eval() and disabled legacy repr object support by default, reflecting a broader pattern of deserialization risk in the project.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
According to the ZeroPath summary, later jsonpickle releases changed behavior to avoid eval() and disabled legacy repr object support by default, addressing the unsafe deserialization path tied to CVE-2021-47952. The source does not provide a specific date for when these changes were released.
Adi Malyanker and Shay Reuven published an exploit for remote code execution in Python jsonpickle 2.0.0, describing abuse of the "py/repr" deserialization path to execute attacker-controlled code. The report said no patch was available at the time and noted testing on Windows and Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourceexploit-db.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.