epyt-flow@0.15.0b1 vulnerabilities

EPyT-Flow -- EPANET Python Toolkit - Flow

  • latest version

    0.16.1

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the epyt-flow package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Deserialization of Untrusted Data

    epyt-flow is an EPyT-Flow -- EPANET Python Toolkit - Flow

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the type parameter in my_load_from_json. An attacker can execute arbitrary code by supplying a malicious JSON body containing a __type__ field that triggers dynamic import and instantiation of attacker-controlled classes. This can be exploited remotely through the REST API.

    How to fix Deserialization of Untrusted Data?

    Upgrade epyt-flow to version 0.16.1 or higher.

    [,0.16.1)