Remote Code Execution Vulnerability in Package Index Module
CVE-2024-6345
What is CVE-2024-6345?
A vulnerability exists in the package_index module of PyPa's Setuptools affecting versions up to 69.1.1. This flaw enables remote code execution through its download functions, which are designed to retrieve packages via user-defined URLs or standard package index servers. If these functions process inputs that users control, they can unintentionally execute arbitrary commands on the host system. The security issue has been addressed in Setuptools version 70.0, which users are encouraged to upgrade to in order to mitigate risks associated with potential code injection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pypa/setuptools < 70.0
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.0
Timeline
Vulnerability published
