CVE-2022-34982
Description
PyPI package eziod before v0.0.1 contained a third-party-inserted code execution backdoor allowing remote attackers to execute arbitrary code on systems installing the package.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
PyPI package eziod before v0.0.1 contained a third-party-inserted code execution backdoor allowing remote attackers to execute arbitrary code on systems installing the package.
Vulnerability
The eziod package available on PyPI before version v0.0.1 contained a malicious code execution backdoor inserted by a third party. The backdoor was embedded within the package's source code and executed automatically upon installation, without requiring any special configuration or conditions [1].
Exploitation
An attacker with no prior access or authentication could exploit this backdoor simply by convincing a target to install the compromised eziod package via pip. No user interaction beyond the installation step is required; the malicious code runs automatically during the package installation process [1].
Impact
Successful exploitation leads to arbitrary code execution on the system where the package is installed. This gives the attacker full control over the affected system, enabling data theft, further compromise, or use of the system for malicious purposes [1].
Mitigation
The PyPI package eziod was removed after the disclosure, and the secure version is v0.0.1. Users should immediately upgrade to v0.0.1 or later if they have installed any prior version. There is no workaround other than removing the compromised version and upgrading [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- PyPI/ezioddescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- pypi.doubanio.com/simple/requestmitrex_refsource_MISC
- github.com/alexw994/eziod/issues/1mitrex_refsource_MISC
- pypi.org/project/eziod/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.