{"id":"GHSA-2689-cw26-6cpj","summary":"Whoogle allows attackers to execute arbitrary code via supplying a crafted search query","details":"An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.","aliases":["CVE-2024-53305","PYSEC-2026-2048"],"modified":"2026-07-07T17:56:25.343678823Z","published":"2025-04-16T18:31:54Z","database_specific":{"nvd_published_at":"2025-04-16T18:16:03Z","cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-04-16T20:38:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53305"},{"type":"WEB","url":"https://github.com/benbusby/whoogle-search/commit/223f00c3c0533423114f99b30c561278bc0b42ba"},{"type":"WEB","url":"https://fern89.github.io/posts/whoogle-rce"},{"type":"WEB","url":"https://gist.github.com/fern89/ca5fe76ad81b4bc363e7341e523a1651"},{"type":"PACKAGE","url":"https://github.com/benbusby/whoogle-search"}],"affected":[{"package":{"name":"whoogle-search","ecosystem":"PyPI","purl":"pkg:pypi/whoogle-search"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.1"}]}],"versions":["0.1.0","0.1.3","0.1.4","0.2.0","0.2.1","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.6.0","0.7.0","0.7.1","0.7.2","0.7.3","0.7.4","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-2689-cw26-6cpj/GHSA-2689-cw26-6cpj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}