GHSA-hgc3-hp6x-wpgx

    Dashboard / Vulnerabilities / GHSA-hgc3-hp6x-wpgx

    GHSA-hgc3-hp6x-wpgx

    Published: 3 Nov 2021Last Modified: 8 Jul 2026

    Summary: Antilles Dependency Confusion Vulnerability

    Details: ### Potential Impact: Remote code execution. ### Scope of Impact: Open-source project specific. ### Summary Description: A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to a package listed in requirements.txt not existing in the public package index (PyPi). MITRE classifies this weakness as an Uncontrolled Search Path Element (CWE-427) in which a private package dependency may be replaced by an unauthorized package of the same name published to a well-known public repository such as PyPi. The configuration has been updated to only install components built by Antilles, removing all other public package indexes. Additionally, the antilles-tools dependency has been published to PyPi. ### Mitigation Strategy for Customers (what you should do to protect yourself): Remove previous versions of Antilles as a precautionary measure and Update to version 1.0.1 or later. ### Acknowledgement: The Antilles team thanks Kotko Vladyslav for reporting this issue. ### References: https://github.com/lenovo/Antilles/commit/c7b9c5740908b343aceefe69733d9972e64df0b9

    Affected packages

    Package

    Name: antilles-tools

    Purl: pkg:pypi/antilles-tools

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.1

    Affected versions

    1.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hgc3-hp6x-wpgx | CVE-DB