Security advisories
Current and historical public security advisories for QWED open-source packages. Each record provides affected and patched version guidance, verified remediation steps, disclosure timelines, and authoritative source references.
Operating Discipline
Report → Validate → Fix → Release → Disclose → Verify
Public security advisories
Verified records for qwed and qwed-mcp
| Advisory / Title | Package | Severity | Affected | Fixed | Published | Status | Guidance |
|---|---|---|---|---|---|---|---|
Authenticated Remote Code Execution via Unsafe SymPy parse_expr() CVE-2026-55585 affects qwed 5.1.1. The affected mathematical-expression parsing paths did not sufficiently restrict caller-controlled expressions. In applicable deployments, this could allow arbitrary code execution in the API server process. The issue is fixed in qwed 5.1.2. | qwed | HighCVSS 8.8 | 5.1.1 | 5.1.2 | 14 June 2026 | Fixed | Read guidance |
Unsafe SymPy parse_expr() Remote Code Execution via Unsanitized Math Expression Input CVE-2026-55546 affects qwed-mcp 0.2.0. The affected mathematical-expression verification library function did not sufficiently restrict untrusted expression input. In a downstream integration that passes attacker-controlled input to the affected function, this could allow arbitrary code execution in the process running qwed-mcp. The issue is fixed in qwed-mcp 0.2.1. | qwed-mcp | CriticalCVSS 9.8 | 0.2.0 | 0.2.1 | 13 June 2026 | Fixed | Read guidance |
Authenticated Remote Code Execution via Unsafe SymPy parse_expr()
qwedCVE-2026-55585 affects qwed 5.1.1. The affected mathematical-expression parsing paths did not sufficiently restrict caller-controlled expressions. In applicable deployments, this could allow arbitrary code execution in the API server process. The issue is fixed in qwed 5.1.2.
Unsafe SymPy parse_expr() Remote Code Execution via Unsanitized Math Expression Input
qwed-mcpCVE-2026-55546 affects qwed-mcp 0.2.0. The affected mathematical-expression verification library function did not sufficiently restrict untrusted expression input. In a downstream integration that passes attacker-controlled input to the affected function, this could allow arbitrary code execution in the process running qwed-mcp. The issue is fixed in qwed-mcp 0.2.1.
Verify your installed version
If you manage deployments incorporating qwed or qwed-mcp, check your lockfiles and build environments against the fixed versions above. Detailed verification commands and remediation considerations are documented on each individual advisory page.
References and reporting
For information regarding responsible vulnerability disclosure and our security lifecycle, visit Security at QWED.