© 2025-2026 PySpect
First version without a known vulnerability: 83.0.0
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
Fixed in: 83.0.0
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
Fixed in: 78.1.1, 250a6d17978f9f6ac3ac887091f2d32886fbbb0b
setuptools vulnerable to Command Injection via package URL
Fixed in: 70.0.0
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
Fixed in: 65.5.1, 43a9c9bfa6aa626ec2a22540bea28d2ca77964be
Setuptools vulnerable to Man-in-the-middle attacks
Fixed in: 0.7