VDB

GCVE-110-PYPI-2026-000268

GCVE-110-PYPI-2026-000268
Advisory Published
Vulnetix · Advisory published October 9, 2026
[PY-SETUP-IMPORTLIB-EXEC] setup.py uses importlib/imp to load a module and immediately exec/compile/eval it: documented PyPI obfuscated-execution TTP. Benign setup.py imports pinned dependencies plainly; dynamic module load + exec at install time is a staged payload.

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-94Improper Control of Generation of Code ('Code Injection')

Affected Products

VendorProductVersionsPlatforms
pypiApiLogicServer17.3.3 (affected), 17.4.11 (affected)—

References

advisory
web

Browse GCVE Records

3,476 records in the GCVE database · Updated October 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›