Critical severity9.8OSV Advisory· Published Feb 9, 2019· Updated Jun 17, 2026
CVE-2019-7653
CVE-2019-7653
Description
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- cpe:2.3:a:rdflib_project:rdflib:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- Range: =4.2.2-1
Patches
Vulnerability mechanics
References
4- bugs.debian.org/921751nvdExploitMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00019.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/12/msg00026.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/4535-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.