{"id":"CVE-2023-43364","details":"main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.","aliases":["GHSA-66m2-493m-crh2","PYSEC-2023-262"],"modified":"2026-08-12T03:51:17.843976972Z","published":"2023-12-12T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43364.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43364.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-66m2-493m-crh2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43364"},{"type":"FIX","url":"https://github.com/ArjunSharda/Searchor/commit/16016506f7bf92b0f21f51841d599126d6fcd15b"},{"type":"FIX","url":"https://github.com/ArjunSharda/Searchor/pull/130"},{"type":"PACKAGE","url":"https://github.com/nexis-nexis/Searchor-2.4.0-POC-Exploit-"},{"type":"PACKAGE","url":"https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/arjunsharda/searchor","events":[{"introduced":"0"},{"fixed":"6af21315c75df555ea024eaff632f75b6ff8d417"},{"fixed":"16016506f7bf92b0f21f51841d599126d6fcd15b"}],"database_specific":{"cpe":"cpe:2.3:a:arjunsharda:searchor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.4.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.4.2","v2.4.1","v2.4.0","v2.3.2","v2.3.1","v2.3.0","v2.2.3","v2.2.2","v2.1.1f","v2.2.0","v2.1.6","v2.1.5","v2.1.4","v2.1.3f","v2.1.3","v2.1.2f","v2.1.2","v2.1.1","v2.1.0","v2.0.2","v2.0.0","v1.4.0","v1.3.0","v1.2.0","v1.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43364.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}