PYSEC-2025-6

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/colabrun/PYSEC-2025-6.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2025-6
Published
2025-02-26T21:45:57.721824Z
Modified
2025-02-26T20:59:48Z
Summary
Exfiltrates cookies to hardcoded IP address
Details

Published in 2021, the colabrun package is a Python library that exfiltrates user cookies to a hardcoded IP address. The package was found to exfiltrate user data to a hardcoded server, which could be used for malicious purposes.

References
Credits
    • Mike Fiedler - COORDINATOR

Affected packages

PyPI / colabrun

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected