LOW 3.9 PyPI
tqdm CLI arguments injection attack
GHSA-g7vv-2v7x-gj9p · CVE-2024-34062 · PYSEC-2026-1976
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Any optional non-boolean CLI arguments (e.g. --delim, --buf-size, --manpath) are passed through python's eval, allowing arbitrary code execution. Example:
python -m tqdm --manpath="\" + str(exec(\"import os\nos.system('echo hi && killall python3')\")) + \""
Patches
https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316 released in tqdm>=4.66.3
Workarounds
None
References
References
- WEB https://github.com/tqdm/tqdm/security/advisories/GHSA-g7vv-2v7x-gj9p
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-34062
- WEB https://github.com/tqdm/tqdm/commit/4e613f84ed2ae029559f539464df83fa91feb316
- PACKAGE https://github.com/tqdm/tqdm
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PA3GIGHPWAHCTT4UF57LTPZGWHAX3GW6
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRECVQCCESHBS3UJOWNXQUIX725TKNY6
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VA337CYUS4SLRFV2P6MX6MZ2LKFURKJC
Ready to move
Start Securing
Free, no credit card | First findings in minutes