PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
History

Mon, 09 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Description PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the assessment lifecycle state before allowing execution. There is no check to ensure that the assessment has started, is not expired, or the submission window is currently open.
Title PlaciPy Code Execution Allowed Without Assessment Active State Validation
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-09T20:58:09.000Z

Reserved: 2026-02-05T19:58:01.642Z

Link: CVE-2026-25809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-09T21:15:49.957

Modified: 2026-02-09T21:55:30.093

Link: CVE-2026-25809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.