Junglewise Threat Intelligence

CVE-2024-6345: PYSEC-2026-1918 - setuptools vulnerable to Command Injection via package URL

CVE-2024-6345 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: setuptools (PyPI). Vendors: PyPI.

Executive brief

setuptools vulnerable to Command Injection via package URL

Affected products

  • PyPI setuptools

Related threats