In RPyC before 6.0.0, when a server exposes a method that calls the attribute named array for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
{ "binaries": [ { "binary_name": "python3-rpyc", "binary_version": "3.4.4-1" } ] }
{ "binaries": [ { "binary_name": "python3-rpyc", "binary_version": "5.0.1-3" } ] }
{ "binaries": [ { "binary_name": "python3-rpyc", "binary_version": "5.3.1-1" } ] }
{ "binaries": [ { "binary_name": "python3-rpyc", "binary_version": "6.0.1-1" } ] }