CVE Explorer
CVE-2026-30960
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations functionalities. The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Function Interface). Due to Improper Input Validation and External Control of Code Generation, an attacker can supply malicious parameters or instruction sequences through the CFFI layer. Since the library
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 4 assertions
{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/3/descriptions/0
{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-695","description":"CWE-695: Use of Low-Level Functionality","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"rssn","vendor":"Apich-Organization","versions":[{"status":"affected","version":"< 0.2.9"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":9.4,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
4 source assertions{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/3/descriptions/0
{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-695","description":"CWE-695: Use of Low-Level Functionality","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/problemTypes/2/descriptions/0
Source references
3 source assertions{"name":"https://github.com/Apich-Organization/rssn/releases/tag/v0.2.9","tags":["x_refsource_MISC"],"url":"https://github.com/Apich-Organization/rssn/releases/tag/v0.2.9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/references/1
{"name":"https://github.com/Apich-Organization/rssn/security/advisories/GHSA-9c4h-pwmf-m6fj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Apich-Organization/rssn/security/advisories/GHSA-9c4h-pwmf-m6fj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/references/0
{"name":"https://rustsec.org/advisories/RUSTSEC-2026-0038.html","tags":["x_refsource_MISC"],"url":"https://rustsec.org/advisories/RUSTSEC-2026-0038.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8295264304f46c858c77be02456a5feccaa10fbcbce2e25fa6b964d6b814b375 · sha256:2dea75a6f80cdb6c… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.