The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade graphite-web | Jul 30, 2024 | Sep 27, 2013 |
| Freebsd | — | Upgrade py31-graphite-webUpgrade py27-graphite-webUpgrade py32-graphite-webUpgrade py26-graphite-webUpgrade py33-graphite-web | Dec 10, 2025 | Sep 30, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub