VulnWatch VulnWatch
← Back to dashboard
Critical github · GHSA-xjw9-4gw8-4rqx

Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution

Published Feb 19, 2026 CVSS 9.9

Impact:

An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the InMemoryVectorStore filter functionality.

Patches:

The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.

Workarounds:

Avoid using InMemoryVectorStore for production scenarios.

References:

Release python-1.39.4 · microsoft/semantic-kernel · GitHub PR to block use of dangerous attribute names that must not be accessed in filter expressions

Affected AI Products

semantic kernel
Get the weekly digest. Every Monday: top AI security stories of the week. Free.