Code Execution Backdoor in KGExplore Package for Python
CVE-2022-33002
9.8CRITICAL
What is CVE-2022-33002?
The KGExplore package for Python from PyPI versions 0.1.1 and 0.1.2 contains a vulnerability that introduces a code execution backdoor via the request package. This flaw compromises the security of applications leveraging KGExplore, allowing attackers to gain unauthorized access to sensitive user information, including digital currency keys, and facilitating potential privilege escalation. Developers using the affected versions should review their implementations and upgrade to a secure version to mitigate these risks.
