Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
Critical severity
GitHub Reviewed
Published
Feb 19, 2026
in
microsoft/semantic-kernel
•
Updated Jun 8, 2026
Description
Published by the National Vulnerability Database
Feb 19, 2026
Published to the GitHub Advisory Database
Feb 19, 2026
Reviewed
Feb 19, 2026
Last updated
Jun 8, 2026
Impact:
An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within the
InMemoryVectorStorefilter functionality.Patches:
The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.
Workarounds:
Avoid using
InMemoryVectorStorefor production scenarios.References:
Release python-1.39.4 · microsoft/semantic-kernel · GitHub
PR to block use of dangerous attribute names that must not be accessed in filter expressions
References