-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| spam | pip | = 2.0.2 | |
| spam | pip | = 4.0.2 |
The advisory indicates malware execution occurred at install time. In Python packages, the setup.py script's setup() function is the primary entry point that executes during installation. While no specific code is available, the attack vector (install-time execution) and standard packaging conventions strongly suggest malicious code was placed in the setup routine. The confidence is high because this is the canonical way to execute code during pip install, though without direct code evidence there's inherent uncertainty.
KEV Misses 88% of Exploited CVEs- Get the report