Pipreqs is a utility tool for automatically generating Python package requirements from source code, and its vulnerability profile is narrow, centered on a single product with exposure limited to path-handling logic. The durable signal reflects a dependency-scanning tool's attack surface: uncontrolled search-path elements where the tool resolves package locations without proper validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pipreqs Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31543CRITICAL A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server. | Jun 30, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pipreqs Project.
Media articles that mention a CVE ID that affects a product developed by Pipreqs Project — matched by CVE ID, not by vendor name.