VDB

GCVE-110-PYPI-2026-017722

GCVE-110-PYPI-2026-017722
Advisory Published
Vulnetix · Advisory published October 3, 2026
The PyPI package `whatsnewt` (version 3.15.2) was flagged as malicious by automated package analysis (2 corroborating detection(s)). Installing it may execute attacker-controlled code via setup.py or bundled Python sources. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-912Embedded Malicious CodeCWE-506Embedded Malicious CodeCWE-94Improper Control of Generation of Code ('Code Injection')

Affected Products

VendorProductVersionsPlatforms
pypiwhatsnewt3.15.1 (affected), 3.15.2 (affected)—

References

advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›