CVE-2013-1630

pyshop < 0.7.1 - Remote Code Execution via Unverified HTTP Package Download

Title source: llm
STIX 2.1

Description

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

Scores

EPSS 0.0208
EPSS Percentile 79.2%

Details

CWE
CWE-20
Status published
Products (8)
guillaume_gauvrit/pyshop 0.1
guillaume_gauvrit/pyshop 0.2
guillaume_gauvrit/pyshop 0.3
guillaume_gauvrit/pyshop 0.4
guillaume_gauvrit/pyshop 0.5
guillaume_gauvrit/pyshop 0.6
guillaume_gauvrit/pyshop < 0.7
pypi/pyshop 0 - 0.7.1PyPI
Published Aug 06, 2013
Tracked Since Feb 18, 2026