CVE-2026-9147 is a code injection vulnerability in scikit-hep uproot affecting versions up to and including 5.7.4. Uproot dynamically generates Python class source code from ROOT TStreamerInfo records embedded in ROOT files and compiles that code at runtime. Certain file-controlled streamer metadata fields, including streamer element names, are interpolated into the generated Python source without safe quoting such as repr() or the !r format specifier. A crafted ROOT file can therefore embed expression-breaking content in streamer metadata so that, when uproot generates and invokes the corresponding reader method, attacker-controlled Python code is evaluated in the context of the process handling the file. The issue is a classic code generation injection flaw arising from unsafe incorporation of untrusted metadata into executable source.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python proof-of-concept exploit for CVE-2026-9147 affecting uproot <= 5.7.4. The vulnerability is a code-injection issue in uproot’s runtime-generated Python class source derived from ROOT TStreamerInfo metadata. The exploit is file-based rather than network-based: it crafts a malicious ROOT file whose streamer element name contains Python expression-breaking content. When a vulnerable application opens that file, uproot reads the attacker-controlled metadata, generates Python source for the embedded class (ExploitTarget), and executes the injected expression when the generated read_members method is invoked. Repository structure is minimal and purposeful: README.md documents the vulnerability, impact, and expected output; exploit_walkthrough.md provides step-by-step reproduction guidance; requirements.txt pins dependencies including uproot==5.7.4; root_file_builder.py constructs malicious_tstreamerinfo.root by manually building TStreamerInfo/TStreamerElement objects and embedding the injected member name; run_poc.py is the main execution harness that resets marker.txt, builds the malicious ROOT file, opens it with uproot, forces generation of the file-backed class, invokes read_members, catches the expected DeserializationError, and verifies that marker.txt was written. Main exploit capability: local arbitrary Python code execution in the context of the process that parses the crafted ROOT file. The PoC payload is intentionally benign and only writes marker.txt with the string 'executed through uproot generated read_members'. No reverse shell, network callback, persistence, or credential theft logic is present. Because the payload is hardcoded and simple, the exploit is best classified as OPERATIONAL rather than weaponized. The exploit is genuine, not merely a detector, and demonstrates end-to-end trigger plus evidence of execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.