Executive brief
web2py remote code execution via hardcoded encryption key in session.connect function
Affected products
- PyPI web2py
Junglewise Threat Intelligence
CVE-2016-3953 · Severity: low · CVSS 3.1 · Published 2026-06-29
Technologies: web2py (PyPI). Vendors: PyPI.
web2py remote code execution via hardcoded encryption key in session.connect function