CVE-2026-26030
Impact:
An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the InMemoryVectorStore filter functionality.
Patches:
The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.
Workarounds:
Avoid using InMemoryVectorStore for production scenarios.
References:
Release python-1.39.4 · microsoft/semantic-kernel · GitHub
PR to block use of dangerous attribute names that must not be accessed in filter expressions
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx, https://nvd.nist.gov/vuln/detail/CVE-2026-26030, https://github.com/microsoft/semantic-kernel/pull/13505, https://github.com/microsoft/semantic-kernel, https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4
