VYPR

Unearth

by Frostming

CVEs (1)

  • CVE-2023-45805HigOct 20, 2023
    risk 0.44cvss 7.8epss 0.01

    pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another…