Loading...
Loading...
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.
August 6, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-1630
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.