The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-10-12. NVD baseline CVSS 9.8; sources differ by 0.0.
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.
October 11, 2022
May 20, 2025
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| d8s-asns | 0.1.0 ... 0.7.0 (9 versions) | — | — |
| democritus-csv | 2021.1.21 | — | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-42037
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.