id: PYSEC-2022-43027 details: The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0. affected: - package: name: d8s-lists ecosystem: PyPI purl: pkg:pypi/d8s-lists ranges: - type: ECOSYSTEM events: - introduced: "0" versions: - 0.1.0 - 0.2.0 - 0.3.0 - 0.4.0 - 0.5.0 - 0.6.0 - 0.6.1 - 0.6.2 - 0.7.0 - 0.8.0 references: - type: PACKAGE url: https://pypi.org/project/democritus-dicts/ - type: EVIDENCE url: https://github.com/democritus-project/d8s-lists/issues/18 - type: REPORT url: https://github.com/democritus-project/d8s-lists/issues/18 - type: PACKAGE url: https://pypi.org/project/d8s-lists/ aliases: - CVE-2022-42039 modified: "2023-06-05T01:12:48.913872Z" published: "2022-10-11T22:15:00Z"