Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pipreqs 代码问题漏洞
Vulnerability Description
pipreqs是Vadim Kravcenko个人开发者的一个库,可以根据任何项目的导入生成 piprequirements.txt 文件。 pipreqs v0.3.0 版本到 v0.4.11 版本存在安全漏洞,该漏洞源于通过一些操作可以向生成的 requirements.txt 文件注入指定的 PyPI 包。
CVSS Information
N/A
Vulnerability Type
N/A