id: PYSEC-2022-216 details: The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. affected: - package: name: perdido ecosystem: PyPI purl: pkg:pypi/perdido ranges: - type: ECOSYSTEM events: - introduced: 0.0.1 - fixed: 0.0.3 references: - type: PACKAGE url: https://pypi.org/project/perdido/ - type: REPORT url: https://github.com/ludovicmoncla/perdido/issues/1 - type: WEB url: http://pypi.doubanio.com/simple/request aliases: - CVE-2022-34054 modified: "2022-07-05T19:16:00Z" published: "2022-06-24T21:15:00Z"