25.1.1
16 years ago
2 months ago
Known vulnerabilities in the pip package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Arbitrary Command Injection when installing a package from a Mercurial VCS URL. An attacker can inject arbitrary configuration options to the How to fix Arbitrary Command Injection? Upgrade | [,23.3) |
Affected versions of this package are vulnerable to Improper Input Validation. Splitting on unicode separators in git references could be maliciously used to install a different revision on the repository. How to fix Improper Input Validation? Upgrade | [,21.1) |
Affected versions of this package are vulnerable to Directory Traversal via How to fix Directory Traversal? Upgrade | [,19.2) |