CVE advisoryCRITICAL
CVE-2018-1000802
CPython shutil Command Injection Vulnerability.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A command injection vulnerability exists in Python's shutil module, allowing attackers to potentially inject arbitrary files onto a system or cause a denial of service. This occurs when unfiltered user input is passed to the `make_archive` function. Confirmation is needed to determine if this function is used with untr