—
PYSEC-2020-61
Quick fix
PYSEC-2020-61 — lookatme: upgrade to the fixed version with the command below.
pip install --upgrade 'lookatme>=72fe36b784b234548d49dae60b840c37f0eb8d84'Details
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/lookatme
Introduced in:
0Fixed in: 72fe36b784b234548d49dae60b840c37f0eb8d84Fix
pip install --upgrade 'lookatme>=72fe36b784b234548d49dae60b840c37f0eb8d84'References
- https://github.com/d0c-s4vage/lookatme/security/advisories/GHSA-c84h-w6cr-5v8q[ADVISORY]
- https://github.com/d0c-s4vage/lookatme/commit/72fe36b784b234548d49dae60b840c37f0eb8d84[FIX]
- https://pypi.org/project/lookatme/#history[PACKAGE]
- https://github.com/d0c-s4vage/lookatme/releases/tag/v2.3.0[WEB]
- https://github.com/d0c-s4vage/lookatme/pull/110[WEB]