Critical CVE issued for hallucinated SQLite vulnerability
research.jfrog.com
Critical CVE issued for hallucinated SQLite vulnerability
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.
0 comments
No comments yet.