requests-2.32.4-py3-none-any.whl: 1 vulnerabilities (highest severity is: 4.4)
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 58/100
Hướng nghiên cứu
Bắt đầu bằng cách xác định khai báo dependency trong repository sql-cli được đường dẫn quét tham chiếu đến và xác nhận requests 2.32.4 được ghim ở đâu. Xem lại chi tiết CVE-2026-25645 và cập nhật dependency trực tiếp lên bản phát hành đã sửa lỗi 2.33.0, sau đó chạy các test hiện có của dự án hoặc quét dependency để xác minh rằng phiên bản dễ bị tấn công đã không còn.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Vulnerable Library - requests-2.32.4-py3-none-any.whl
Python HTTP for Humans.
Library home page: https://files.pythonhosted.org/packages/7c/e4/56027c4a6b4ae70ca9de302488c5ca95ad4a39e190093d6c1a8ace08341b/requests-2.32.4-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/sql-cli
Path to vulnerable library: /tmp/ws-ua_20260518195424_ZCYUWM/python_XKNQIE/202605181954251/env/lib/python3.12/site-packages/requests-2.32.4.dist-info
Found in HEAD commit: 68212e0c681da02608aa39ca6a7234d5a082124e
Vulnerabilities
| Vulnerability | Severity | CVSS |
Dependency | Type | Fixed in (requests version) | Remediation Possible** |
|---|---|---|---|---|---|---|
| CVE-2026-25645 | Medium |
4.4 | requests-2.32.4-py3-none-any.whl | Direct | https://github.com/psf/requests.git - v2.33.0 | ✅ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-25645
Vulnerable Library - requests-2.32.4-py3-none-any.whl
Python HTTP for Humans.
Library home page: https://files.pythonhosted.org/packages/7c/e4/56027c4a6b4ae70ca9de302488c5ca95ad4a39e190093d6c1a8ace08341b/requests-2.32.4-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/sql-cli
Path to vulnerable library: /tmp/ws-ua_20260518195424_ZCYUWM/python_XKNQIE/202605181954251/env/lib/python3.12/site-packages/requests-2.32.4.dist-info
Dependency Hierarchy:
- ❌ requests-2.32.4-py3-none-any.whl (Vulnerable Library)
Found in HEAD commit: 68212e0c681da02608aa39ca6a7234d5a082124e
Found in base branch: main
Vulnerability Details
Requests is a HTTP library. Prior to version 2.33.0, the "requests.utils.extract_zipped_paths()" utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call "extract_zipped_paths()" directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set "TMPDIR" in their environment to a directory with restricted write access.
Publish Date: 2026-03-25
URL: CVE-2026-25645
CVSS 3 Score Details (4.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026-03-25
Fix Resolution: https://github.com/psf/requests.git - v2.33.0
⛑️ Automatic Remediation will be attempted for this issue.
:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.
- Ngôn ngữ chính
- Python
- Star
- 9
- Fork
- 24
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của opensearch-project/sql-cli
-
Mend: dependency security vulnerability
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Mend: dependency security vulnerability
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 58/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 20/100
opensearch-project/sql-cli#59 · 1 bình luận · 1 reaction ·
-
Update version on PyPiCó thể làm lại được @zhongnansu đã nhận 186 ngày trước và không có pull request nào đang mở. Đang mởdocumentation enhancement
opensearch-project/sql-cli#45 · 3 bình luận · 1 người được giao ·
-
Github Action Deprecation: actions/upload-artifact@v3Có thể làm lại được @Swiddis đã nhận 697 ngày trước và không có pull request nào đang mở. Đang mở
opensearch-project/sql-cli#31 · 1 bình luận · 1 người được giao ·
Tất cả issue của opensearch-project/sql-cli
Issue tương tự
-
Update Python support to 3.15Đang mởpython-version
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug javascript P2-medium python release:v3.1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
adrirubio/claude-deck#546 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: desktop area: website priority: P2 type: feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
appandflow/stim#3411 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 Dưới một giờ Mức phù hợp với người mới 88/100
baptistehamon/lsapy#185 ·
Maintainer thường phản hồi trong vòng 1 ngày
CVSS