PYPI · AUGUST 2026 · EARLY WARNING

piccolo-admin Privilege Escalation Issue: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
piccolo-admin (pypi)
Affected versions
< 1.14.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.10.3, <= 0.10.3 or >= 0.10.4, <= 0.10.4 or >= 0.10.5, <= 0.10.5 or >= 0.10.6, <= 0.10.6 or >= 0.10.7, <= 0.10.7 or >= 0.10.8, <= 0.10.8 or >= 0.10.9, <= 0.10.9 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.11.10, <= 0.11.10 or >= 0.11.11, <= 0.11.11 or >= 0.11.12, <= 0.11.12 or >= 0.11.13, <= 0.11.13 or >= 0.11.2, <= 0.11.2 or >= 0.11.3, <= 0.11.3 or >= 0.11.4, <= 0.11.4 or >= 0.11.5, <= 0.11.5 or >= 0.11.6, <= 0.11.6 or >= 0.11.7, <= 0.11.7 or >= 0.11.8, <= 0.11.8 or >= 0.11.9, <= 0.11.9 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.13.0, <= 0.13.0 or >= 0.13.1, <= 0.13.1 or >= 0.13.2, <= 0.13.2 or >= 0.14.0, <= 0.14.0 or >= 0.15.0, <= 0.15.0 or >= 0.15.1, <= 0.15.1 or >= 0.15.2, <= 0.15.2 or >= 0.16.0, <= 0.16.0 or >= 0.16.1, <= 0.16.1 or >= 0.17.0, <= 0.17.0 or >= 0.18.0, <= 0.18.0 or >= 0.18.1, <= 0.18.1 or >= 0.18.2, <= 0.18.2 or >= 0.19.0, <= 0.19.0 or >= 0.19.1, <= 0.19.1 or >= 0.19.2, <= 0.19.2 or >= 0.19.3, <= 0.19.3 or >= 0.19.4, <= 0.19.4 or >= 0.19.5, <= 0.19.5 or >= 0.19.6, <= 0.19.6 or >= 0.2.0, <= 0.2.0 or >= 0.20.0, <= 0.20.0 or >= 0.21.0, <= 0.21.0 or >= 0.22.0, <= 0.22.0 or >= 0.22.1, <= 0.22.1 or >= 0.22.2, <= 0.22.2 or >= 0.23.0, <= 0.23.0 or >= 0.24.0, <= 0.24.0 or >= 0.25.0, <= 0.25.0 or >= 0.26.0, <= 0.26.0 or >= 0.26.1, <= 0.26.1 or >= 0.27.0, <= 0.27.0 or >= 0.28.0, <= 0.28.0 or >= 0.29.0, <= 0.29.0 or >= 0.29.1, <= 0.29.1 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.3.2, <= 0.3.2 or >= 0.3.3, <= 0.3.3 or >= 0.3.4, <= 0.3.4 or >= 0.3.5, <= 0.3.5 or >= 0.3.6, <= 0.3.6 or >= 0.3.7, <= 0.3.7 or >= 0.3.8, <= 0.3.8 or >= 0.30.0, <= 0.30.0 or >= 0.31.0, <= 0.31.0 or >= 0.31.1, <= 0.31.1 or >= 0.31.2, <= 0.31.2 or >= 0.32.0, <= 0.32.0 or >= 0.33.0, <= 0.33.0 or >= 0.33.1, <= 0.33.1 or >= 0.34.0, <= 0.34.0 or >= 0.35.0, <= 0.35.0 or >= 0.36.0, <= 0.36.0 or >= 0.37.0, <= 0.37.0 or >= 0.38.0, <= 0.38.0 or >= 0.39.0, <= 0.39.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.40.0, <= 0.40.0 or >= 0.41.0, <= 0.41.0 or >= 0.42.0, <= 0.42.0 or >= 0.43.0, <= 0.43.0 or >= 0.44.0, <= 0.44.0 or >= 0.45.0, <= 0.45.0 or >= 0.45.1, <= 0.45.1 or >= 0.45.2, <= 0.45.2 or >= 0.46.0, <= 0.46.0 or >= 0.47.0, <= 0.47.0 or >= 0.48.0, <= 0.48.0 or >= 0.49.0, <= 0.49.0 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.50.0, <= 0.50.0 or >= 0.51.0, <= 0.51.0 or >= 0.52.0, <= 0.52.0 or >= 0.53.0, <= 0.53.0 or >= 0.54.0, <= 0.54.0 or >= 0.55.0, <= 0.55.0 or >= 0.56.0, <= 0.56.0 or >= 0.57.0, <= 0.57.0 or >= 0.58.0, <= 0.58.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.6.6, <= 0.6.6 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.8.1, <= 0.8.1 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.10.0, <= 1.10.0 or >= 1.11.0, <= 1.11.0 or >= 1.12.0, <= 1.12.0 or >= 1.13.0, <= 1.13.0 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.4.0, <= 1.4.0 or >= 1.5.0, <= 1.5.0 or >= 1.6.0, <= 1.6.0 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.9.0, <= 1.9.0 or >= 1.9.1, <= 1.9.1 or >= 1.2.0, < 1.3.2 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.2.0, < 1.3.2 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1
Patched version
Not yet available
GHSA-2GH4-JMWQ-RR8W

An early warning has been issued for a privilege escalation issue in the piccolo-admin package. This issue allows non-superuser admins to access live session tokens in plaintext, enabling them to impersonate users and self-promote to superuser.

What happened

The piccolo-admin package reportedly has a critical vulnerability that permits non-superuser admins to access live session tokens in plaintext. This flaw is due to the lack of rejection for GET requests in the superuser_validators function. The issue is under investigation and has not yet been exploited in the wild. The affected versions span a wide range, from versions less than 1.14.0 to various versions between 0.1.0 and 1.3.2.

This vulnerability poses a significant risk as it allows unauthorized admins to gain superuser privileges by impersonating legitimate users. The exposure assessment should focus on identifying which versions of piccolo-admin are in use within your systems and determining if any non-superuser admins have access to the affected endpoints.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If piccolo-admin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using piccolo-admin versions less than 1.14.0 or any version between 0.1.0 and 1.3.2.

What should I do right now?

Review your piccolo-admin package versions, restrict GET requests in the superuser_validators function, and implement additional security measures for session tokens. Monitor primary sources for updates.

Is there an official fix available?

No official fix has been published yet. Continue to monitor the sources for updates.

How can I prevent unauthorized access to session tokens?

Ensure proper restriction of GET requests in the superuser_validators function and implement additional security measures as recommended.

Sources

Join the 0Day waitlist →

← Back to all threats