Tkinter is a GUI toolkit bundled with Python that provides cross-platform graphical interface capabilities; its vulnerability profile is centered on a single core product with sparse historical disclosure. The durable signal reflects weakness classes around embedded malicious code and exposure of sensitive information, which are characteristic of supply-chain and packaging concerns rather than defects in the toolkit's core functionality. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tkinter Package over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16061HIGH tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | May 29, 2018 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tkinter Package.
Media articles that mention a CVE ID that affects a product developed by Tkinter Package — matched by CVE ID, not by vendor name.