{"id":"PYSEC-2017-7","details":"An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.","aliases":["CVE-2017-7235","GHSA-5mc5-5j6c-qmf9"],"modified":"2023-11-08T03:59:24.135930Z","published":"2017-03-23T04:59:00Z","references":[{"type":"WEB","url":"https://github.com/Anorov/cloudflare-scrape/releases/tag/1.8.0"},{"type":"REPORT","url":"https://github.com/Anorov/cloudflare-scrape/issues/97"},{"type":"WEB","url":"http://www.securityfocus.com/bid/97191"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5mc5-5j6c-qmf9"}],"affected":[{"package":{"name":"cfscrape","ecosystem":"PyPI","purl":"pkg:pypi/cfscrape"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.6"},{"fixed":"1.8.0"}]}],"versions":["1.6.6","1.6.7","1.6.8","1.7.0","1.7.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/cfscrape/PYSEC-2017-7.yaml"}}],"schema_version":"1.7.3"}