Critical severity9.8NVD Advisory· Published May 8, 2022· Updated Jun 17, 2026
CVE-2022-28470
CVE-2022-28470
Description
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
marcadorPyPI | < 0.14 | 0.14 |
Affected products
2- PyPI/marcador packagedescription
Patches
Vulnerability mechanics
References
8- github.com/joajfreitas/marcador/issues/5nvdExploitIssue TrackingThird Party AdvisoryWEB
- pypi.doubanio.com/simple/requestnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-57qv-h9m7-jxfgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-28470ghsaADVISORY
- github.com/joajfreitas/marcador/commit/84d84549c6c6d765abc9243ac7e85d810f32d6e7ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/marcador/PYSEC-2022-185.yamlghsaWEB
- pypi.org/project/marcadorghsaWEB
- pypi.org/project/marcador/nvdProduct
News mentions
0No linked articles in our index yet.