CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:semantic_kernel:*:*:*:*:*:python:*:*

History

03 Mar 2026, 16:32

Type Values Removed Values Added
References () https://github.com/microsoft/semantic-kernel/pull/13505 - () https://github.com/microsoft/semantic-kernel/pull/13505 - Issue Tracking, Patch
References () https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4 - () https://github.com/microsoft/semantic-kernel/releases/tag/python-1.39.4 - Release Notes
References () https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx - () https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx - Patch, Vendor Advisory
Summary
  • (es) Semantic Kernel, el SDK de Python de kernel semántico de Microsoft, tiene una vulnerabilidad de ejecución remota de código en versiones anteriores a la 1.39.4, específicamente dentro de la funcionalidad de filtro de 'InMemoryVectorStore'. El problema ha sido solucionado en la versión 'python-1.39.4'. Los usuarios deberían actualizar a esta versión o una superior. Como solución alternativa, evite usar 'InMemoryVectorStore' para escenarios de producción.
CPE cpe:2.3:a:microsoft:semantic_kernel:*:*:*:*:*:python:*:*
First Time Microsoft semantic Kernel
Microsoft

19 Feb 2026, 17:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 17:24

Updated : 2026-03-03 16:32


NVD link : CVE-2026-26030

Mitre link : CVE-2026-26030

CVE.ORG link : CVE-2026-26030


JSON object : View

Products Affected

microsoft

  • semantic_kernel
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')