Executive brief
pyp2spec is a tool used by developers to create Fedora RPM packages for Python projects. A security flaw allows malicious Python packages to include hidden commands in their metadata that are executed when a developer attempts to build or even just inspect the package. This could lead to a full compromise of the developer's workstation, potentially exposing sensitive credentials used for software distribution.
Technical details
pyp2spec prior to version 0.14.1 is vulnerable to code injection because it fails to escape RPM macro directives when importing PyPI package metadata (such as the 'summary' field) into generated RPM spec files. An attacker can craft a malicious PyPI package containing RPM macros (e.g., %{lua:...} or %{expand:...}) in its metadata. When a user runs any RPM-related tool on the generated spec file—including rpmbuild, rpm -q, or rpmbuild -bs—the RPM engine evaluates these macros, leading to arbitrary command execution. This vulnerability is particularly impactful for Fedora packagers as it could lead to the theft of SSH keys or build system credentials. The issue is fixed in version 0.14.1.
Affected products
- befeleme pyp2spec < 0.14.1
Timeline
- 2026-04-21: patched: Version 0.14.1 released
- 2026-04-23: advisory: GitHub Security Advisory published
- 2026-05-09: disclosed: CVE published to NVD