CVE-2023-49297 is a critical deserialization vulnerability affecting PyDrive2 versions prior to 1.16.2. It allows for arbitrary code execution if a maliciously crafted YAML file is present in the same directory where PyDrive2 initializes GoogleAuth, or if loaded via LoadSettingsFile. This vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. There are no known public exploits, Metasploit modules, or Nuclei templates, and it is not listed in CISA's KEV catalog. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16.2CPE matchmatch criteria | cpe:2.3:a:iterative:pydrive2:*:*:*:*:*:*:*:* | ||
1.17.0CPE matchmatch criteria | cpe:2.3:a:iterative:pydrive2:1.17.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.