Junglewise Threat Intelligence

CVE-2016-3953: PYSEC-2026-570 - web2py remote code execution via hardcoded encryption key in session.connect function

CVE-2016-3953 · Severity: low · CVSS 3.1 · Published 2026-06-29

Technologies: web2py (PyPI). Vendors: PyPI.

Executive brief

web2py remote code execution via hardcoded encryption key in session.connect function

Affected products

  • PyPI web2py

Related threats