Skip to content

CVE-2025–50817: vulnerability in python-future package #485

@xiaoxi-private

Description

@xiaoxi-private

There is an vulnerability CVE-2025–50817 discovered in the python-future package that affects the package. Since that package already reaches its end of support, would there be any fix taken by PyHive regarding this vulnerability?

References
https://www.wiz.io/vulnerability-database/cve/cve-2025-50817
https://medium.com/@abcd_68700/cve-2025-50817-python-future-module-arbitrary-code-execution-via-unintended-import-of-test-py-f0818ea93cf4
https://nvd.nist.gov/vuln/detail/CVE-2025-50817

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions