An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the InMemoryVectorStore filter functionality.
The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.
Avoid using InMemoryVectorStore for production scenarios.
Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions
{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-19T19:34:14Z",
"nvd_published_at": "2026-02-19T17:24:50Z",
"severity": "CRITICAL"
}