Code Execution Vulnerability in Perdido Package by PyPI
CVE-2022-34054
9.8CRITICAL
What is CVE-2022-34054?
The Perdido package, available on PyPI versions 0.0.1 to 0.0.2, is vulnerable due to a code execution backdoor embedded within the request package. This security flaw permits malicious attackers to exploit the vulnerability, potentially leading to unauthorized access to sensitive user data, including digital currency keys, and may allow for privilege escalation within affected systems.
