Home ยป Database

AVID-2026-R1159

Description

Vulnerability CVE-2022-42037

Details

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

Reason for inclusion in AVID: CVE-2022-42037 documents a code-execution backdoor introduced into the Python PyPI package d8s-asns (version 0.1.0) via a third-party backdoor (democritus-csv). This is a software supply chain vulnerability in a Python package that could be pulled into AI stacks as a dependency, thereby impacting general-purpose AI systems. The report includes explicit security implications and references (NVD, PyPI pages, issue tracker).

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
Systemn/a

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-10-11
  • Version: 0.3.3
  • AVID Entry