Skip to main content

Arbitrary code execution when activating a virtual environment after install a wheel

Project description

venvasion

Arbitrary code execution when activating a virtual environment after install a wheel.

This package exists to demonstrate that you should never build a virtual environment or install packages from untrusted sources: You don't even need to run a python interpreter to trigger the code execution.

Usage:

uv venv test-venv
. test-venv/bin/activate
uv pip install venvasion
. test-venv/bin/activate # oops!

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

venvasion-0.1.1.tar.gz (1.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

venvasion-0.1.1-py3-none-any.whl (2.7 kB view details)

Uploaded Python 3

File details

Details for the file venvasion-0.1.1.tar.gz.

File metadata

  • Download URL: venvasion-0.1.1.tar.gz
  • Upload date:
  • Size: 1.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.5.4

File hashes

Hashes for venvasion-0.1.1.tar.gz
Algorithm Hash digest
SHA256 86e4422249ec6055cb288f55003913379f4de2c8c33059cc5898a66234bf6c1f
MD5 b2bc07854ae2c36531b5aa6ce7653877
BLAKE2b-256 8828fa4aa113bcab52010858994a6319ed94047379efd0eb06999fd53e5fbc71

See more details on using hashes here.

File details

Details for the file venvasion-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: venvasion-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 2.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.5.4

File hashes

Hashes for venvasion-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 43d3cd767c8730e4cab2984d441deb9d3db7660022b4a9d2d7a4742229a1f2a8
MD5 9abc7100f7688492091d42d35e3963e2
BLAKE2b-256 53a578973b7f8eab066f1d3ab494249f1701e0a498cdb4fb7b85fb9c9f261b1d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page