Developer Tools & Libraries
Remote Code Execution
Command Injection in GitHub repository Nuitka/Nuitka prior to 0.9
Command Injection in GitHub repository Nuitka prior to 0.9.
.png)
Overview
Command Injection in GitHub repository Nuitka prior to 0.9.
The main() function uses the eval() function which can lead to contextual code execution, allowing an attacker to gain access to a system and execute commands with the privileges of the running program by setting NUITKA_PYTHONPATH, NUITKA_NAMESPACES, or NUITKA_PTH_IMPORTED to a malicious payload string. This can lead to backdoors, reverse shells or reading/writing to privileged files.
Vulnerability details
Command Injection in GitHub repository Nuitka prior to 0.9. The main() function uses the eval() function which can lead to contextual code execution, allowing an attacker to gain access to a system and execute commands with the privileges of the running
Disclosure timeline
2022-06-04 Reported On
2022-06-05 Made Public On
2022-06-27 Fixed On
References
Credits
Debjeet Banerjee
















