VDB

GCVE-110-PYPI-2026-017134

GCVE-110-PYPI-2026-017134
Advisory Published
Vulnetix · Advisory published October 3, 2026
[PY-SETUP-IMPORTLIB-EXEC] setup.py uses importlib/imp to load a module and immediately exec/compile/eval it: documented PyPI obfuscated-execution TTP. Benign setup.py imports pinned dependencies plainly; dynamic module load + exec at install time is a staged payload.

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-94Improper Control of Generation of Code ('Code Injection')

Affected Products

VendorProductVersionsPlatforms
pypineuralosd1.0.6 (affected), 1.0.10 (affected), 1.0.9 (affected), 1.1.0 (affected), 1.2.0 (affected), 1.2.1 (affected), 1.2.2 (affected), 1.2.3 (affected), 1.2.4 (affected), 1.3.2 (affected), 1.3.1 (affected), 1.3.4 (affected), 1.3.4 (affected), 1.3.5 (affected), 1.4.0 (affected)—

References

advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›