democritus-project / d8s-utility

Democritus functions for working with utility functions.
GNU Lesser General Public License v3.0
0 stars 0 forks source link

code execution backdoor #10

Open di1l0o opened 2 years ago

di1l0o commented 2 years ago

We discovered a potential code execution backdoor in version 0.1.0 of the project, the backdoor is the democritus-file-system package. Attackers can upload democritus-file-system packages containing arbitrary malicious code. For the safety of this project, the democritus-file-system package has been uploaded by us.

image

The democritus-file-system package can be successfully installed using pip install d8s-utility==0.1.0

image

Suggestion: remove version 0.1.0 of this project in PyPI