PatchSiren cyber security CVE debrief
CVE-2026-42301 befeleme CVE debrief
CVE-2026-42301 describes a build-time code execution issue in pyp2spec before 0.14.1. The tool wrote PyPI package metadata into generated Fedora RPM spec files without escaping RPM macro directives. When a packager runs rpmbuild, those directives can be evaluated, allowing a malicious package to execute commands on the build machine. The issue was patched in pyp2spec 0.14.1.
- Vendor
- befeleme
- Product
- pyp2spec
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
Fedora/RPM packagers, Python packaging maintainers, CI/CD owners, and anyone using pyp2spec to generate spec files from untrusted or third-party Python packages.
Technical summary
According to the CVE description and GitHub advisory references, pyp2spec versions prior to 0.14.1 copied PyPI metadata such as the summary field into generated RPM spec files without escaping RPM macro syntax. Because RPM spec processing evaluates macro directives during rpmbuild, attacker-controlled metadata could be interpreted as commands in the packaging context. The vulnerability is classified with CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H and mapped to CWE-20 and CWE-94 in the supplied source data.
Defensive priority
High. This is a build-system compromise risk that can affect package signing, release pipelines, and downstream artifacts if pyp2spec is used on untrusted input.
Recommended defensive actions
- Upgrade pyp2spec to version 0.14.1 or later.
- Review any automation that generates RPM spec files from PyPI metadata and treat package metadata as untrusted input.
- Inspect generated spec files in packaging pipelines for unexpected RPM macro directives before running rpmbuild.
- Limit where builds run and apply least privilege to packaging environments to reduce impact if macro evaluation is triggered.
- If pyp2spec was used on third-party packages, audit recent build jobs and outputs for unexpected commands or spec-file content.
Evidence notes
The description is supported by the official CVE/NVD record and GitHub Security Advisory references included in the source corpus. The GitHub release tag for v0.14.1 is cited as the patch release, and the advisory URL is provided as the remediation reference. Timing context uses the supplied CVE published/modified timestamp of 2026-05-09T04:16:25.923Z; no other issue date is inferred.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42301 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42301
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42301 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42301
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/befeleme/pyp2spec/releases/tag/v0.14.1
-
Source reference
Unverified legacy reference
URL: https://github.com/befeleme/pyp2spec/security/advisories/GHSA-r35x-v8p8-xvhw
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.