CVE-2015-20107 - CVE House
Back to Database
Status published High CVE-2015-20107

In Python (aka CPython) up to 3.10.8, the mailcap module...

Vulnerability Description

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-20107

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

python, active iq unified manager, ontap select deploy administration utility, snapcenter, fedora
Vulnerable Versions:
3.7.0, 3.8.0, 3.9.0, 3.10.0, 35, 36, 37

Timeline

Official Publish: April 13th, 2022
Last Modified: November 3rd, 2025
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.