setuptools dependency).
setuptools <78.1.1 and thus rely on a compromised dependency. In some cases there is a chance that source-builds would fail due to an exploit of the closely related CVE-2025-47273, or become arbitrarily modified.setuptools>=80.4
{
"nvd_published_at": null,
"github_reviewed_at": "2025-05-28T21:07:05Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-1395"
],
"github_reviewed": true
}