Intel

AIKIDO-2026-610076

DynamicExpresso.Core is vulnerable to Unsafe Reflection

Unsafe ReflectionGHSA-v37m-7mgv-vwv9 Published Yesterday

88

High Risk

This Affects:

DOTNETDynamicExpresso.Core
2.9.0 - 2.19.5
Fixed in 2.19.6
Are you affected? Scan for Free

TL;DR

DynamicExpresso enforces a default reflection restriction through DisableReflectionVisitor, but lambda bodies are parsed by a second, internally-created Interpreter that never receives this visitor. An expression that uses InterpreterOptions.LambdaExpressions together with a dynamic parameter (LateBindObject or an IDynamicMetaObjectProvider value such as ExpandoObject) can therefore reach arbitrary reflection and OS command execution from inside a lambda, even though the identical expression is blocked at the top level. The fix moves visitor registration from the Interpreter instance into the shared, cloned ParserSettings, so lambda and nested-lambda parsing keep DisableReflectionVisitor enforced by default.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable InterpreterOptions.LambdaExpressions with a dynamic value such as LateBindObject or an IDynamicMetaObjectProvider parameter.

Background info

DynamicExpresso.Core is vulnerable to Unsafe Reflection in versions 2.9.0 - 2.19.5.

How to fix this

Upgrade the DynamicExpresso.Core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform