VDB
EN
HIGH 7.8

PYSEC-2024-226

상세

Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / pymatgen
최초 영향 버전: 0 수정 버전: c231cbd3d5147ee920a37b6ee9dd236b376bcf5a
수정 pip install --upgrade 'pymatgen>=c231cbd3d5147ee920a37b6ee9dd236b376bcf5a'

참고