Hi, The following vulnerability was published for urwid. CVE-2026-9323[0]: | The urwid web display backend (urwid/display/web.py) generates web | session identifiers (urwid_id) in Screen.start() by concatenating | two random.randrange(10**9) calls that use Python's Mersenne Twister | PRNG, which is not cryptographically secure. Each call consumes | approximately 30 bits of PRNG state, and the Mersenne Twister | internal state is approximately 19,937 bits, so an attacker who | observes approximately 334 session IDs (for example via the X-Urwid- | ID HTTP response header) can fully reconstruct the internal state | and predict all past and future session IDs (Path B). The same | identifier is also used as the filename of a FIFO created in the | world-listable /tmp directory (for example | /tmp/urwid375487765176907690.in), so any local user on the host can | list /tmp to enumerate active session tokens directly (Path A). With | a valid session ID, an attacker can read the victim's terminal | screen via the polling endpoint, inject keystrokes into the victim's | session (yielding OS-level code execution with the session owner's | privileges if the session runs a shell), and inject exit sequences | or flood the FIFO to terminate or crash the session. A prior Bandit | S311 warning on this usage was suppressed with # noqa: S311 rather | than fixed https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv https://github.com/urwid/urwid/pull/1128 Fixed by: https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9 (4.0.2) If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-9323 https://www.cve.org/CVERecord?id=CVE-2026-9323 Please adjust the affected versions in the BTS as needed.