VYPR
High severityNVD Advisory· Published Aug 6, 2013· Updated Jun 16, 2026

CVE-2013-1630

CVE-2013-1630

Description

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pyshopPyPI
< 0.7.10.7.1

Affected products

8
  • cpe:2.3:a:guillaume_gauvrit:pyshop:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:guillaume_gauvrit:pyshop:*:*:*:*:*:*:*:*range: <=0.7
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:guillaume_gauvrit:pyshop:0.6:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 0.7.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.