WhisperX tag archive

#CWE-704

This page collects WhisperX intelligence signals tagged #CWE-704. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-16 02:22:37 · GitHub Issues

1. Apache Superset Code Flaw: User Input to Python Typecast Opens Door to NaN Injection, Undefined Behavior

A static analysis scan has flagged a medium-severity vulnerability in Apache Superset's codebase, where unsanitized user input flows directly into Python's `bool()`, `float()`, or `complex()` typecast functions. This specific path allows a potential attacker to inject Python's special 'not-a-number' (NaN) value into th...