Intel

AIKIDO-2026-575375

ty is vulnerable to Use After Free

Use After FreeGHSA-vxvm-j4xq-q7m4 Published Yesterday

78

High Risk

This Affects:

PYTHONty
0.0.1 - 0.0.83
Fixed in 0.0.84
Are you affected? Scan for Free

TL;DR

ty's incremental analysis engine can access freed memory when it processes a specially crafted Python project, caused by a use-after-free in Salsa, the incremental computation library ty relies on. Opening such a project in an editor or running ty check --fix against it triggers the flaw without executing any of the project's Python code. The stale memory access can result in arbitrary code execution with the privileges of the user running ty. The fix upgrades ty to a Salsa release that resolves the use-after-free.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use ty to analyze a Python project from an untrusted source.

Background info

ty is vulnerable to Use After Free in versions 0.0.1 - 0.0.83.

How to fix this

Upgrade the ty library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform