VDB

GCVE-110-PYPI-2026-015980

GCVE-110-PYPI-2026-015980
Advisory Published
Vulnetix · Advisory published August 27, 2026
[P-PY-SETUP-EXEC] setup.py spawns a subprocess at install time (download-and-execute vector) — matched: findings["id"] = subprocess.check_output(["id"], text=True, timeout=5).strip()

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
pypibq-build-probe-vrp-20260.2.0 (affected)

References

advisory

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›