Vulnerability Details CVE-2020-15271
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.1%
CVSS Severity
CVSS v3 Score 9.3
CVSS v2 Score 9.3
Products affected by CVE-2020-15271
-
cpe:2.3:a:lookatme_project:lookatme:0.0.1
-
cpe:2.3:a:lookatme_project:lookatme:0.0.2
-
cpe:2.3:a:lookatme_project:lookatme:0.1.0
-
cpe:2.3:a:lookatme_project:lookatme:0.1.1
-
cpe:2.3:a:lookatme_project:lookatme:0.2.0
-
cpe:2.3:a:lookatme_project:lookatme:0.3.0
-
cpe:2.3:a:lookatme_project:lookatme:0.4.0
-
cpe:2.3:a:lookatme_project:lookatme:0.5.0
-
cpe:2.3:a:lookatme_project:lookatme:1.0.0
-
cpe:2.3:a:lookatme_project:lookatme:1.0.1
-
cpe:2.3:a:lookatme_project:lookatme:1.1.0
-
cpe:2.3:a:lookatme_project:lookatme:1.1.1
-
cpe:2.3:a:lookatme_project:lookatme:1.2.0
-
cpe:2.3:a:lookatme_project:lookatme:1.2.1
-
cpe:2.3:a:lookatme_project:lookatme:1.3.0
-
cpe:2.3:a:lookatme_project:lookatme:2.0.0
-
cpe:2.3:a:lookatme_project:lookatme:2.1.0
-
cpe:2.3:a:lookatme_project:lookatme:2.2.0