VYPR
Unrated severityNVD Advisory· Published Oct 11, 2022· Updated May 19, 2025

CVE-2022-42039

CVE-2022-42039

Description

The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The d8s-lists package on PyPI version 0.1.0 includes a backdoor via the democritus-dicts dependency, enabling arbitrary code execution.

Vulnerability

The d8s-lists package for Python, distributed on PyPI, included a potential code-execution backdoor in version 0.1.0 [1]. The backdoor is introduced through the democritus-dicts package, which is a dependency loaded by the project [2]. When a user installs d8s-lists==0.1.0, the democritus-dicts package is also installed, containing arbitrary malicious code [2].

Exploitation

An attacker can upload a malicious democritus-dicts package to PyPI with the same name and version required by d8s-lists [2]. When a user runs pip install d8s-lists==0.1.0, the attacker's package is automatically downloaded and executed as part of the dependency resolution [2]. No additional user interaction or special privileges are needed beyond installing the package.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the user who installed the package [2]. This can lead to full compromise of the user's system, including data exfiltration, installation of further malware, or other malicious actions, depending on the payload.

Mitigation

Version 0.1.0 is affected; no fixed version has been released [2]. The project maintainers suggest removing version 0.1.0 from PyPI [2]. Users should avoid installing or using d8s-lists==0.1.0 and instead use a different or later version if available. Check the PyPI page for updates [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.