tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, allowing arbitrary code execution. This issue is only locally exploitable and had been addressed in release version 4.66.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-tqdm | Aug 22, 2024 | May 3, 2024 |
| Debian | — | Upgrade tqdm | May 15, 2025 | May 3, 2024 |
| Suse | — | Upgrade python313-tqdmUpgrade python-tqdm-bash-completionUpgrade python311-tqdm | May 31, 2024 | May 3, 2024 |
| Ubuntu | — | Upgrade python3-tqdm (Ubuntu Pro) | Jan 17, 2025 | May 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub