Skip to content

uniapi version 1.0.7 contained an information harvesting script.

High severity GitHub Reviewed Published Jan 27, 2025 to the GitHub Advisory Database • Updated Jan 27, 2025

Package

pip uniapi (pip)

Affected versions

= 1.0.7

Patched versions

None

Description

uniapi version 1.0.7 introduces code that would execute on import of the module and download a script from a remote URL, and would then execute the downloaded script in a thread. The downloaded script would harvest system information and POST the information to another remote URL. This code was found in the PyPI release artifacts and was not present in the public GitHub repository.

References

Published to the GitHub Advisory Database Jan 27, 2025
Reviewed Jan 27, 2025
Last updated Jan 27, 2025

Severity

High

EPSS score

Weaknesses

No CWEs

CVE ID

No known CVE

GHSA ID

GHSA-gvvw-rr8m-fj76

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.