voidly
NIST · via Voidly Atlas

CVE-2021-47952

This is the agency's own public-domain data, curated and made citable by Voidly. Voidly adds no independent claim — always verify against the linked canonical source.
cve id
CVE-2021-47952
published
2026-05-16T16:16:21.520
last modified
2026-05-16T16:16:21.520
status
Received
description
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.
cvss score
9.8
cvss severity
CRITICAL
cvss vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cwes
CWE-94
cpe count
0

Cite this record

CVE-2021-47952 — CRITICAL. NIST, via Voidly Atlas — Surveillance & Digital-Rights Watch. Retrieved 2026-06-07, https://voidly.ai/atlas/federal/nvd-cves/CVE-2021-47952

@misc{voidly_nvd_cves_CVE202147952,
  title        = {CVE-2021-47952 — CRITICAL},
  author       = {{Voidly}},
  howpublished = {\url{https://voidly.ai/atlas/federal/nvd-cves/CVE-2021-47952}},
  note         = {Source: NIST National Vulnerability Database, https://nvd.nist.gov/vuln/detail/CVE-2021-47952. Public domain (17 U.S.C. §105); re-surfaced under CC BY 4.0},
  urldate      = {2026-06-07},
  year         = {2026}
}

Also available as JSON/BibTeX/APA: API record. Source data is U.S. federal public domain (17 U.S.C. §105). Re-surfaced by Voidly under CC BY 4.0.