GHSA-h57c-v2v3-5v3v

Suggest an improvement
Source
https://github.com/advisories/GHSA-h57c-v2v3-5v3v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h57c-v2v3-5v3v/GHSA-h57c-v2v3-5v3v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h57c-v2v3-5v3v
Aliases
  • CVE-2026-6878
Published
2026-04-23T00:31:20Z
Modified
2026-05-05T16:10:19.381931Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()
Details

A vulnerability was identified in ByteDance verl up to 0.7.1. Affected is the function mathequal of the file primemath/grader.py. The manipulation leads to a sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit is publicly available and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "github_reviewed": true,
    "severity": "LOW",
    "nvd_published_at": "2026-04-23T00:16:47Z",
    "cwe_ids": [
        "CWE-95"
    ],
    "github_reviewed_at": "2026-04-30T20:52:35Z"
}
References

Affected packages

PyPI / verl

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.7.1

Affected versions

0.*
0.1rc0
0.1rc2
0.1
0.2
0.2.0.post1
0.2.0.post2
0.3.0.post0
0.3.0.post1
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-h57c-v2v3-5v3v/GHSA-h57c-v2v3-5v3v.json"