Open d3m0n-r00t opened 3 years ago
@zsdonghao @Laicheng0830 Did you have any chance to look at it? If it is a valid vulnerability in the context of tensorlayer we (at Snyk would like to add it to our vulnerability db
@zsdonghao Any comments on this?????
@d3m0n-r00t This is a potential security hole, you can fix it with Pull requests.
@Laicheng0830 I have created a fix with huntr. Please find the fix here (https://github.com/418sec/tensorlayer/pull/1).
Attaching the original disclosure for reference:
https://github.com/418sec/huntr/pull/1791 and https://www.huntr.dev/bounties/1-pip-tensorlayer/
New Issue Checklist
Issue Description
Possibility of arbitrary code execution in
tensorlayer
.Issue problem and fix explained here (https://github.com/418sec/tensorlayer/pull/1)