Code Execution Vulnerability in RootInteractive Package by PyPI
CVE-2022-32997
9.8CRITICAL
What is CVE-2022-32997?
The RootInteractive package available in PyPI, versions 0.0.5 to 0.0.19b0, has been identified to contain a vulnerability that allows for unauthorized code execution. This issue arises from a backdoor incorporated via the request package, enabling attackers to gain access to sensitive user information, including digital currency keys. Furthermore, the vulnerability can facilitate privilege escalation, posing a significant risk to users and their data security.
