{"id":"PYSEC-2022-43056","details":"The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.","aliases":["CVE-2022-30877"],"modified":"2025-10-09T08:24:04.785178Z","published":"2022-06-08T18:15:00Z","references":[{"type":"REPORT","url":"https://github.com/OrkoHunter/keep/issues/85"},{"type":"ADVISORY","url":"https://pypi.org/project/keep"},{"type":"ADVISORY","url":"http://pypi.doubanio.com/simple/request"}],"affected":[{"package":{"name":"keep","ecosystem":"PyPI","purl":"pkg:pypi/keep"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1","1.2","1.3","1.3.1","1.4","1.4.1","2","2.1","2.1.1","2.1.2","2.1.3","2.10","2.10.1","2.4.0","2.4.1","2.4.2","2.5","2.5.1","2.5.2","2.6","2.6.1","2.7","2.8","2.9","2.11"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/keep/PYSEC-2022-43056.yaml"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}