GHSA-vqwp-45wm-r9r5LowCVSS 3.6

Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission

Published
June 4, 2026
Last Modified
July 15, 2026

🔗 CVE IDs covered (1)

📋 Description

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

🎯 Affected products1

  • pip/streamlit:< 1.53.1

🔗 References (12)