Vulnerability CVE-2023-31543


Published: 2023-06-30

Description:
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.

 References:
https://github.com/bndr/pipreqs/pull/364
https://gist.github.com/adeadfed/ccc834440af354a5638f889bee34bafe

Copyright 2026, cxsecurity.com

 

Back to Top