VDB
Sign up
MEDIUM4.3

PYSEC-2026-1990

trytond allows remote attackers to obtain sensitive trace-back (server setup) information

Quick fix

PYSEC-2026-1990 — trytond: upgrade to the fixed version with the command below.

pip install --upgrade 'trytond>=6.0.70'

Details

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/trytond
Introduced in: 0Fixed in: 6.0.70
Fixpip install --upgrade 'trytond>=6.0.70'

References