VDB
Sign up
—

PYSEC-2018-100

Quick fix

PYSEC-2018-100 — rope: upgrade to the fixed version with the command below.

pip install --upgrade 'rope>=0.11.0'

Details

base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/rope
Introduced in: 0Fixed in: 0.11.0
Fixpip install --upgrade 'rope>=0.11.0'

References