Skip to content

CVE-2025-50817, High level vulnerability #14

@navya-sriv

Description

@navya-sriv

Hi guys,
It appears that bce-python-sdk is affected by CVE-2025-50817 due to its dependency on future. The vulnerability arises because future can automatically import a local test.py file, which could lead to arbitrary code execution if a malicious file is present in the environment. Could you please take a look and plan a fix or mitigation for this in the library?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions