{"id":"GHSA-67r3-h899-9w95","summary":"Embedded Malicious Code in ctx","details":"The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.","modified":"2022-06-02T15:46:06Z","published":"2022-06-02T15:46:06Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-06-02T15:46:06Z"},"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/ctx/PYSEC-2022-199.yaml"},{"type":"WEB","url":"https://python-security.readthedocs.io/pypi-vuln/index-2022-05-24-ctx-domain-takeover.html"}],"affected":[{"package":{"name":"ctx","ecosystem":"PyPI","purl":"pkg:pypi/ctx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.1.2-1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-67r3-h899-9w95/GHSA-67r3-h899-9w95.json"}}],"schema_version":"1.9.0"}