id: PYSEC-2026-3390 published: "2026-07-09T16:49:46.008923Z" modified: "2026-07-13T16:07:21.126552Z" aliases: - CVE-2014-6633 - GHSA-m9jj-5qvj-5fhx summary: Tryton vulnerable to arbitrary command execution details: The `safe_eval` function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the `collection.domain` in the webdav module or (2) the formula field in the `price_list` module. affected: - package: name: tryton ecosystem: PyPI purl: pkg:pypi/tryton ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.4.15 - introduced: 2.6.0 - fixed: 2.6.14 - introduced: 2.8.0 - fixed: 2.8.11 - introduced: 3.2.0 - fixed: 3.2.3 versions: - 1.0.0 - 1.0.1 - 1.0.2 - 1.0.3 - 1.0.4 - 1.0.5 - 1.0.6 - 1.0.7 - 1.0.8 - 1.0.9 - 1.2.0 - 1.2.1 - 1.2.10 - 1.2.2 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.7 - 1.2.8 - 1.2.9 - 1.4.0 - 1.4.1 - 1.4.10 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5 - 1.4.6 - 1.4.7 - 1.4.8 - 1.4.9 - 1.6.0 - 1.6.1 - 1.6.2 - 1.6.3 - 1.6.4 - 1.6.5 - 1.6.6 - 1.6.7 - 1.6.8 - 1.6.9 - 1.8.0 - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - 1.8.5 - 1.8.6 - 1.8.7 - 1.8.8 - 1.8.9 - 2.0.0 - 2.0.1 - 2.0.10 - 2.0.11 - 2.0.12 - 2.0.2 - 2.0.3 - 2.0.4 - 2.0.5 - 2.0.6 - 2.0.7 - 2.0.8 - 2.0.9 - 2.2.0 - 2.2.1 - 2.2.10 - 2.2.11 - 2.2.12 - 2.2.13 - 2.2.2 - 2.2.3 - 2.2.4 - 2.2.5 - 2.2.6 - 2.2.7 - 2.2.8 - 2.2.9 - 2.4.0 - 2.4.1 - 2.4.10 - 2.4.11 - 2.4.12 - 2.4.13 - 2.4.14 - 2.4.2 - 2.4.3 - 2.4.4 - 2.4.5 - 2.4.6 - 2.4.7 - 2.4.8 - 2.4.9 - 2.6.0 - 2.6.1 - 2.6.10 - 2.6.11 - 2.6.12 - 2.6.13 - 2.6.2 - 2.6.3 - 2.6.4 - 2.6.5 - 2.6.6 - 2.6.7 - 2.6.8 - 2.6.9 - 2.8.0 - 2.8.1 - 2.8.10 - 2.8.2 - 2.8.3 - 2.8.4 - 2.8.5 - 2.8.6 - 2.8.7 - 2.8.8 - 2.8.9 - 3.2.0 - 3.2.1 - 3.2.2 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2014-6633 - type: WEB url: https://github.com/tryton/trytond/commit/19fc2a01357b7638041953326e404f51d96fad06 - type: WEB url: https://github.com/tryton/trytond/commit/3e4c2b7e8c7b3358597a0d484fa98f45483ee92a - type: WEB url: https://bugs.tryton.org/issue4155 - type: WEB url: https://github.com/pypa/advisory-database/tree/main/vulns/trytond/PYSEC-2018-59.yaml - type: PACKAGE url: https://github.com/tryton/trytond - type: WEB url: http://www.tryton.org/posts/security-release-for-issue4155.html - type: PACKAGE url: https://pypi.org/project/tryton - type: ADVISORY url: https://github.com/advisories/GHSA-m9jj-5qvj-5fhx severity: - type: CVSS_V3 score: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N