tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, allowing arbitrary code execution. This issue is only locally exploitable and had been addressed in release version 4.66.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-py3-tqdm | Aug 22, 2024 | May 3, 2024 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | May 3, 2024 | |
| Suse | — | suse-upgrade-python-tqdm-bash-completionsuse-upgrade-python311-tqdmsuse-upgrade-python313-tqdm | May 31, 2024 | May 3, 2024 |
| Ubuntu | ubuntu-pro-upgrade-python3-tqdm | Jan 17, 2025 | May 3, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub