Code Execution Vulnerability in ML-Scanner Package by PyPI
CVE-2022-33000
9.8CRITICAL
What is CVE-2022-33000?
The ML-Scanner package in PyPI versions 0.1.0 to 0.1.5 is susceptible to a code execution backdoor due to vulnerabilities in the request package. This flaw enables malicious actors to execute arbitrary code, potentially compromising sensitive user data, including user credentials and digital currency keys. Additionally, there are risks of privilege escalation, increasing the severity of the potential impact on systems utilizing this package.
