SCA: security update for mesop (GHSA-f3mf-hm6v-jfhh)

high Tenable Cloud Security Plugin ID 421248

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Mesop is a Python-based UI framework that allows users to build web applications. A class pollution
vulnerability in Mesop prior to version 0.14.1 allows attackers to overwrite global variables and class
attributes in certain Mesop modules during runtime. This vulnerability could directly lead to a denial of
service (DoS) attack against the server. Additionally, it could also result in other severe consequences
given the application's implementation, such as identity confusion, where an attacker could impersonate an
assistant or system role within conversations. This impersonation could potentially enable jailbreak
attacks when interacting with large language models (LLMs). Just like the Javascript's prototype
pollution, this vulnerability could leave a way for attackers to manipulate the intended data-flow or
control-flow of the application at runtime and lead to severe consequences like remote code execution when
gadgets are available. Users should upgrade to version 0.14.1 to obtain a fix for the issue.
(CVE-2025-30358)

See Also

https://github.com/advisories/GHSA-f3mf-hm6v-jfhh

Plugin Details

Severity: High

ID: 421248

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 3/27/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.2

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2025-30358

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/27/2025

Vulnerability Publication Date: 3/27/2025

Reference Information

CVE: CVE-2025-30358

cwe: CWE-915