dropbox / dropbox/PyHive

CVE-2025–50817: vulnerability in python-future package

Open
#485 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
1.7k
Forks
545
PR merge metrics
No merged PRs in 30d

Description

There is an vulnerability [CVE-2025–50817](https://github.com/advisories/GHSA-xqrq-4mgf-ff32) discovered in the python-future package that affects the package. Since that package already reaches its end of support, would there be any fix taken by PyHive regarding this vulnerability?

References
https://www.wiz.io/vulnerability-database/cve/cve-2025-50817
https://medium.com/@abcd_68700/cve-2025-50817-python-future-module-arbitrary-code-execution-via-unintended-import-of-test-py-f0818ea93cf4
https://nvd.nist.gov/vuln/detail/CVE-2025-50817

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.