CRITICAL
GHSA-67r3-h899-9w95
Embedded Malicious Code in ctx
Details
The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/ctx
Introduced in:
0.1.2-1No fixed version published yet for ctx (pip). Pin to a known-safe version or switch to an alternative.