Input validation error in Kiwi - #VU150957
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute Python code available in the application environment.
The vulnerability exists due to improper input validation in the BugSystem.tracker_type field when processing user-supplied tracker types. A remote user can supply a crafted Python dotted path to execute Python code available in the application environment.