VDB
GCVE-110-PYPI-2026-017134
GCVE-110-PYPI-2026-017134
Advisory Published
[PY-SETUP-IMPORTLIB-EXEC] setup.py uses importlib/imp to load a module and immediately exec/compile/eval it: documented PyPI obfuscated-execution TTP. Benign setup.py imports pinned dependencies plainly; dynamic module load + exec at install time is a staged payload.
Weaknesses (CWE)
CWE-506Embedded Malicious CodeCWE-94Improper Control of Generation of Code ('Code Injection')
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| pypi | neuralosd | 1.0.6 (affected), 1.0.10 (affected), 1.0.9 (affected), 1.1.0 (affected), 1.2.0 (affected), 1.2.1 (affected), 1.2.2 (affected), 1.2.3 (affected), 1.2.4 (affected), 1.3.2 (affected), 1.3.1 (affected), 1.3.4 (affected), 1.3.4 (affected), 1.3.5 (affected), 1.4.0 (affected) | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.