HIGH8.8
PYSEC-2026-2278
Quick fix
PYSEC-2026-2278 — signify: upgrade to the fixed version with the command below.
pip install --upgrade 'signify>=0.9.2'Details
An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mtrojnar/osslsigncode/releases/tag/2.11[WEB]
- https://github.com/mtrojnar/osslsigncode/issues/475[REPORT]
- https://github.com/ralphje/signify/issues/60[REPORT]
- https://github.com/mtrojnar/osslsigncode/pull/477[FIX]
- https://github.com/ralphje/signify/commit/64f21c0cc06cea0536370686ca3ba7a01e4adaa8[FIX]
- https://github.com/advisories/GHSA-p4hh-mq57-gq8x[ADVISORY]