VDB
Sign up
—

PYSEC-2021-72

Quick fix

PYSEC-2021-72 — pwntools: upgrade to the fixed version with the command below.

pip install --upgrade 'pwntools>=4.3.1'

Details

This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pwntools
Introduced in: 0Fixed in: 4.3.1
Fixpip install --upgrade 'pwntools>=4.3.1'

References