Potential RCE Flaw Patched in PyPI’s GitHub Repository

A vulnerability in the GitHub Actions workflow for PyPI’s source repository could be exploited to perform a malicious pull request and eventually execute arbitrary code on pypi.org, according to a warning from a Japanese security researcher.

read more

Read more: Potential RCE Flaw Patched in PyPI’s GitHub Repository

Story added 2. August 2021, content source with full text you can find at link above.