venvasion
Arbitrary code execution when activating a virtual environment after install a wheel.
This package exists to demonstrate that you should never build a virtual environment or install packages from untrusted sources: You don't even need to run a python interpreter to trigger the code execution.
Usage:
uv venv test-venv
. test-venv/bin/activate
uv pip install --no-build venvasion
. test-venv/bin/activate # oops!
Metadata
Release files for venvasion 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| venvasion-0.1.2.tar.gz | 2.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| venvasion-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 4.7 kB
Release files / venvasion-0.1.2.tar.gz
| Download URL | venvasion-0.1.2.tar.gz |
|---|---|
| Size | 2.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ced9e318fc0fea8723707b2bf9939223725c456cf6be890857d0b8d65578b951
|
|
BLAKE2b-256 checksum How to use checksums |
af4c3ad153204965f7c689510695d8964ab94e83b9c7f1e253f162623620cd6e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.5.4
|
Release files / venvasion-0.1.2-py3-none-any.whl
| Download URL | venvasion-0.1.2-py3-none-any.whl |
|---|---|
| Size | 2.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6e58d3e7dd49ed0fa1287ebc5f01403c943dd7e5aab83b0d7ae5aa7087db5498
|
|
BLAKE2b-256 checksum How to use checksums |
d0bd73847041cb33b71b8f5a4cd60465b71e2daa79675635673b88495ec40579
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.5.4
|