easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
CVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:PPython Setuptools
APPPython0.6.400.6.410.6.420.6.430.6.440.6.450.6.460.6.470.6.480.6.49≤ 0.7b4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2025-47273HIGH7.7same product
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages....
CVE-2026-59890MEDIUM6.1same product
setuptools to pakiet umożliwiający pobieranie, budowanie, instalowanie, uaktualnianie i odinstalowywanie pakie...
CVE-2022-40897MEDIUM5.9same product
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of servic...
CVE-2022-48565CRITICAL9.8PL ✓same vendor
XXE w module plistlib języka Python — wykonanie ataku na dane XML
CVE-2022-37454CRITICAL9.8PL ✓same vendor
Integer overflow w implementacji SHA-3 (XKCP) umożliwiający RCE