PYSEC-2024-154

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/ultralytics/PYSEC-2024-154.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-154
Related
Published
2024-12-10T19:43:04.050935Z
Modified
2024-12-10T19:20:27.097505Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
A number of releases of ultralytics contained malicious crypto miner software.
Details

Ultralytics has identified a supply chain attack affecting affecting multiple versions of the ultralytics package. The compromised versions contained unauthorized code that downloaded and executed cryptocurrency mining software when instantiating YOLO models. This code was injected into the PyPI release artifacts and was not present in the public GitHub repository.

References

Affected packages

PyPI / ultralytics

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.3.41
Fixed
8.3.47

Affected versions

8.*

8.3.41
8.3.42
8.3.43
8.3.44
8.3.45
8.3.46