Security: fgmacedo/python-statemachine
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Restricted-evaluator write-side dunder traversal in SCXML <assign location> corrupts the shared Model class process-wideGHSA-v3qq-3xvg-m77g published
Aug 1, 2026 by fgmacedoCritical -
Unbounded computation (CPU + memory) DoS in the restricted SCXML/native expression evaluatorGHSA-r8gj-366q-cgvj published
Aug 1, 2026 by fgmacedoHigh -
SCXML <data src="file://…"> reads arbitrary local files when loading an untrusted document with the default trusted=False (secure-by-default bypass)GHSA-fj3w-533r-fvf6 published
Aug 1, 2026 by fgmacedoHigh -
python-statemachine SCXML <data expr> Eval InjectionGHSA-v4jc-pm6r-3vj8 published
Jun 17, 2026 by fgmacedoCritical
Learn more about advisories related to fgmacedo/python-statemachine in the GitHub Advisory Database