VDB
Sign up
—

PYSEC-2023-99

Quick fix

PYSEC-2023-99 — pipreqs: upgrade to the fixed version with the command below.

pip install --upgrade 'pipreqs>=0.4.12'

Details

A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pipreqs
Introduced in: 0.3.0Fixed in: 0.4.12
Fixpip install --upgrade 'pipreqs>=0.4.12'

References