Skip to content

QWED's infrastructure is attested by Docker, Snyk, CircleCI, Netlify, Mintlify, Sentry, Cloudflare, CodeRabbit, NVIDIA Inception, Buildkite, GitLab, Heroku, Atlassian.

Security RecordPublic Advisories

Security advisories

Current and historical public security advisories for QWED open-source packages. Each record provides affected and patched version guidance, verified remediation steps, disclosure timelines, and authoritative source references.

Operating Discipline

Report → Validate → Fix → Release → Disclose → Verify

Public security advisories

Verified records for qwed and qwed-mcp

CVE-2026-55585GHSA-q27q-98j4-9pfv
Fixed

Authenticated Remote Code Execution via Unsafe SymPy parse_expr()

Package:qwed
Severity:HIGH (8.8)
Affected:5.1.1
Fixed Version:5.1.2

CVE-2026-55585 affects qwed 5.1.1. The affected mathematical-expression parsing paths did not sufficiently restrict caller-controlled expressions. In applicable deployments, this could allow arbitrary code execution in the API server process. The issue is fixed in qwed 5.1.2.

CVE-2026-55546GHSA-mw6r-2hvm-4rp2
Fixed

Unsafe SymPy parse_expr() Remote Code Execution via Unsanitized Math Expression Input

Package:qwed-mcp
Severity:CRITICAL (9.8)
Affected:0.2.0
Fixed Version:0.2.1

CVE-2026-55546 affects qwed-mcp 0.2.0. The affected mathematical-expression verification library function did not sufficiently restrict untrusted expression input. In a downstream integration that passes attacker-controlled input to the affected function, this could allow arbitrary code execution in the process running qwed-mcp. The issue is fixed in qwed-mcp 0.2.1.

Verify your installed version

If you manage deployments incorporating qwed or qwed-mcp, check your lockfiles and build environments against the fixed versions above. Detailed verification commands and remediation considerations are documented on each individual advisory page.

References and reporting

For information regarding responsible vulnerability disclosure and our security lifecycle, visit Security at QWED.