The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-10-12. NVD baseline CVSS 9.8; sources differ by 0.0.
The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
October 11, 2022
May 20, 2025
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| d8s-domains | 0.1.0 ... 0.6.0 (8 versions) | — | — |
| democritus-urls | 2021.1.21, 2021.1.21b0, 2021.1.25 | — | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-41384
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.