{
  "id": "GHSA-xjw9-4gw8-4rqx",
  "source": "ghsa",
  "source_url": "https://github.com/advisories/GHSA-xjw9-4gw8-4rqx",
  "summary": "Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution",
  "description": "### Impact:\nAn RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the `InMemoryVectorStore` filter functionality.\n\n### Patches:\nThe problem has been fixed in [python-1.39.4](https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4). Users should upgrade this version or higher.\n\n### Workarounds:\nAvoid using `InMemoryVectorStore` for production scenarios.\n\n### References:\n[Release python-1.39.4 · microsoft/semantic-kernel · GitHub](https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4)\n[PR to block use of dangerous attribute names that must not be accessed in filter expressions](https://github.com/microsoft/semantic-kernel/pull/13505)",
  "product": "semantic-kernel",
  "severity": "critical",
  "cvss": {
    "score": 10.0,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "cwes": [
    "CWE-94"
  ],
  "affected": [
    {
      "ecosystem": "pip",
      "name": "semantic-kernel",
      "vulnerable_range": "< 1.39.4",
      "patched_version": "1.39.4"
    }
  ],
  "references": [
    {
      "url": "https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx",
      "ref_type": "advisory",
      "title": null
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26030",
      "ref_type": "other",
      "title": null
    },
    {
      "url": "https://github.com/microsoft/semantic-kernel/pull/13505",
      "ref_type": "pull_request",
      "title": null
    },
    {
      "url": "https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4",
      "ref_type": "release",
      "title": null
    },
    {
      "url": "https://github.com/advisories/GHSA-xjw9-4gw8-4rqx",
      "ref_type": "advisory",
      "title": null
    }
  ],
  "aliases": [
    "CVE-2026-26030"
  ],
  "published_at": "2026-02-19T19:34:14Z",
  "ingested_at": "2026-02-19T20:46:07.029798375Z",
  "raw_source": {
    "credits": [
      {
        "type": "finder",
        "user": {
          "avatar_url": "https://avatars.githubusercontent.com/u/257952426?v=4",
          "events_url": "https://api.github.com/users/amiteliahu/events{/privacy}",
          "followers_url": "https://api.github.com/users/amiteliahu/followers",
          "following_url": "https://api.github.com/users/amiteliahu/following{/other_user}",
          "gists_url": "https://api.github.com/users/amiteliahu/gists{/gist_id}",
          "gravatar_id": "",
          "html_url": "https://github.com/amiteliahu",
          "id": 257952426,
          "login": "amiteliahu",
          "node_id": "U_kgDOD2AKqg",
          "organizations_url": "https://api.github.com/users/amiteliahu/orgs",
          "received_events_url": "https://api.github.com/users/amiteliahu/received_events",
          "repos_url": "https://api.github.com/users/amiteliahu/repos",
          "site_admin": false,
          "starred_url": "https://api.github.com/users/amiteliahu/starred{/owner}{/repo}",
          "subscriptions_url": "https://api.github.com/users/amiteliahu/subscriptions",
          "type": "User",
          "url": "https://api.github.com/users/amiteliahu",
          "user_view_type": "public"
        }
      },
      {
        "type": "finder",
        "user": {
          "avatar_url": "https://avatars.githubusercontent.com/u/69523016?v=4",
          "events_url": "https://api.github.com/users/doredry/events{/privacy}",
          "followers_url": "https://api.github.com/users/doredry/followers",
          "following_url": "https://api.github.com/users/doredry/following{/other_user}",
          "gists_url": "https://api.github.com/users/doredry/gists{/gist_id}",
          "gravatar_id": "",
          "html_url": "https://github.com/doredry",
          "id": 69523016,
          "login": "doredry",
          "node_id": "MDQ6VXNlcjY5NTIzMDE2",
          "organizations_url": "https://api.github.com/users/doredry/orgs",
          "received_events_url": "https://api.github.com/users/doredry/received_events",
          "repos_url": "https://api.github.com/users/doredry/repos",
          "site_admin": false,
          "starred_url": "https://api.github.com/users/doredry/starred{/owner}{/repo}",
          "subscriptions_url": "https://api.github.com/users/doredry/subscriptions",
          "type": "User",
          "url": "https://api.github.com/users/doredry",
          "user_view_type": "public"
        }
      },
      {
        "type": "finder",
        "user": {
          "avatar_url": "https://avatars.githubusercontent.com/u/144804966?v=4",
          "events_url": "https://api.github.com/users/urioren/events{/privacy}",
          "followers_url": "https://api.github.com/users/urioren/followers",
          "following_url": "https://api.github.com/users/urioren/following{/other_user}",
          "gists_url": "https://api.github.com/users/urioren/gists{/gist_id}",
          "gravatar_id": "",
          "html_url": "https://github.com/urioren",
          "id": 144804966,
          "login": "urioren",
          "node_id": "U_kgDOCKGMZg",
          "organizations_url": "https://api.github.com/users/urioren/orgs",
          "received_events_url": "https://api.github.com/users/urioren/received_events",
          "repos_url": "https://api.github.com/users/urioren/repos",
          "site_admin": false,
          "starred_url": "https://api.github.com/users/urioren/starred{/owner}{/repo}",
          "subscriptions_url": "https://api.github.com/users/urioren/subscriptions",
          "type": "User",
          "url": "https://api.github.com/users/urioren",
          "user_view_type": "public"
        }
      }
    ],
    "cve_id": "CVE-2026-26030",
    "cvss": {
      "score": 10.0,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
    },
    "cvss_severities": {
      "cvss_v3": {
        "score": 10.0,
        "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
      },
      "cvss_v4": {
        "score": 0.0,
        "vector_string": null
      }
    },
    "cwes": [
      {
        "cwe_id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      }
    ],
    "description": "### Impact:\nAn RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the `InMemoryVectorStore` filter functionality.\n\n### Patches:\nThe problem has been fixed in [python-1.39.4](https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4). Users should upgrade this version or higher.\n\n### Workarounds:\nAvoid using `InMemoryVectorStore` for production scenarios.\n\n### References:\n[Release python-1.39.4 · microsoft/semantic-kernel · GitHub](https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4)\n[PR to block use of dangerous attribute names that must not be accessed in filter expressions](https://github.com/microsoft/semantic-kernel/pull/13505)",
    "ghsa_id": "GHSA-xjw9-4gw8-4rqx",
    "github_reviewed_at": "2026-02-19T19:34:14Z",
    "html_url": "https://github.com/advisories/GHSA-xjw9-4gw8-4rqx",
    "identifiers": [
      {
        "type": "GHSA",
        "value": "GHSA-xjw9-4gw8-4rqx"
      },
      {
        "type": "CVE",
        "value": "CVE-2026-26030"
      }
    ],
    "nvd_published_at": "2026-02-19T17:24:50Z",
    "published_at": "2026-02-19T19:34:14Z",
    "references": [
      "https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx",
      "https://nvd.nist.gov/vuln/detail/CVE-2026-26030",
      "https://github.com/microsoft/semantic-kernel/pull/13505",
      "https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4",
      "https://github.com/advisories/GHSA-xjw9-4gw8-4rqx"
    ],
    "repository_advisory_url": "https://api.github.com/repos/microsoft/semantic-kernel/security-advisories/GHSA-xjw9-4gw8-4rqx",
    "severity": "critical",
    "source_code_location": "https://github.com/microsoft/semantic-kernel",
    "summary": "Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution",
    "type": "reviewed",
    "updated_at": "2026-02-19T19:34:15Z",
    "url": "https://api.github.com/advisories/GHSA-xjw9-4gw8-4rqx",
    "vulnerabilities": [
      {
        "first_patched_version": "1.39.4",
        "package": {
          "ecosystem": "pip",
          "name": "semantic-kernel"
        },
        "vulnerable_functions": [],
        "vulnerable_version_range": "< 1.39.4"
      }
    ],
    "withdrawn_at": null
  }
}