{"id":"PYSEC-2022-185","details":"marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.","aliases":["CVE-2022-28470","GHSA-57qv-h9m7-jxfg"],"modified":"2025-10-09T08:23:23.365211Z","published":"2022-05-08T20:15:00Z","references":[{"type":"PACKAGE","url":"https://pypi.org/project/marcador/"},{"type":"WEB","url":"http://pypi.doubanio.com/simple/request"},{"type":"REPORT","url":"https://github.com/joajfreitas/marcador/issues/5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-57qv-h9m7-jxfg"}],"affected":[{"package":{"name":"marcador","ecosystem":"PyPI","purl":"pkg:pypi/marcador"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.1"},{"fixed":"0.14"}]}],"versions":["0.5.0","0.5.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/marcador/PYSEC-2022-185.yaml"}}],"schema_version":"1.7.3"}