VYPR

PyPI package

pyshop

pkg:pypi/pyshop

Vulnerabilities (1)

  • CVE-2013-1630Aug 6, 2013
    affected < 0.7.1fixed 0.7.1

    pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.