PyPi: Sqlitedict

CVE-2024-35515

Safety vulnerability ID: 73282

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Sep 18, 2024 Updated at Sep 20, 2024
Scan your Python projects for vulnerabilities →

Advisory

SQLitedict, in all versions, contains an insecure deserialization vulnerability that could allow arbitrary code execution when loading untrusted database files.
#NOTE: The maintainers have acknowledged the issue but opted not to patch it, instead recommending a warning to users about the risks of loading untrusted files.

Affected package

sqlitedict

Latest version: 2.1.0

Persistent dict in Python, backed up by sqlite3 and pickle, multithread-safe.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application