PyInstaller is a widely used tool for packaging Python applications into standalone executables, and its vulnerability exposure centers on permission and privilege-handling defects in how it manages temporary files and resource access during the bundling and execution process. The recurring weakness classes—improper permission assignment, insecure temporary-file creation, and unnecessary privilege elevation—reflect the interaction between the build system and the host environment where packaged applications run. Current exploitation activity, severity trends, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyinstaller over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16784HIGH In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode | Jan 14, 2020 | 7.8 | 23 | NO | NO |
CVE-2023-49797HIGH PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged process, may be tricked by an unp | Dec 9, 2023 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyinstaller.
Media articles that mention a CVE ID that affects a product developed by Pyinstaller — matched by CVE ID, not by vendor name.