Vulnerability DatabaseGHSA-x6xg-3fj2-4pq3

GHSA-x6xg-3fj2-4pq3
Python vulnerability analysis and mitigation

Overview

The exotel project on PyPI was compromised through a user account phishing attack in August 2022. The attackers published a malicious version 0.1.6 of the package that contained harmful code designed to steal environment variables and execute malware during installation (GitHub Advisory, PyPA Advisory).

Technical details

The compromised version 0.1.6 of the exotel package was designed to collect environment variables and download and execute malware during the package installation process. The vulnerability has been assigned a high severity rating (GitHub Advisory).

Impact

When installed, the malicious package version 0.1.6 could steal sensitive environment variables and execute malware on the target system, potentially leading to system compromise and data theft (GitHub Advisory).

Mitigation and workarounds

Users should immediately remove version 0.1.6 of the exotel package if installed. No patched versions have been released, and users should exercise caution when installing any version of this package (GitHub Advisory).

Community reactions

PyPI officially acknowledged the security incident through their Twitter account, alerting users about the compromise (PyPI Tweet).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67511CRITICAL9.6
  • PythonPython
  • cai-framework
NoNoDec 11, 2025
CVE-2025-13780CRITICAL9.1
  • PythonPython
  • cpe:2.3:a:pgadmin:pgadmin
NoYesDec 11, 2025
CVE-2025-67644HIGH7.3
  • PythonPython
  • langgraph-checkpoint-sqlite
NoYesDec 11, 2025
CVE-2025-67720MEDIUM6.5
  • PythonPython
  • pyrofork
NoYesDec 11, 2025
CVE-2025-67485MEDIUM5.3
  • PythonPython
  • mad-proxy
NoNoDec 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management