GHSA-444r-2whx-3685HighCVSS 8.8

Sentry: Superusers can execute arbitrary commands by injecting malicious pickle-serialized objects through audit log entry data parameter

Published
May 10, 2026
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted POST requests to the admin audit log endpoint with base64-encoded compressed pickle payloads in the data field to achieve code execution with application privileges.

🎯 Affected products2

  • pip/sentry:< 8.1.4
  • pip/sentry:>= 8.2.0, < 8.2.2

🔗 References (8)