Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

CVE-2024-22682

PYSEC-2024-25 · CVE-2024-22682

Published · Modified

Description

DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension injection via the custom extension feature.

Ready to move

Start Securing

Free, no credit card | First findings in minutes