PYSEC-2025-8 – pygments-style-solarized
Package
Manager: pip
Name: pygments-style-solarized
Vulnerable Version: =100.10.7
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:R
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
After the owner removed the project from PyPI, another user uploaded a new version with non-working code The `pygments-style-solarized` project was removed from PyPI by its owner on 2021-08-26. The GitHub repository was also updated to show unmaintained, and archived on 2025-08-31. Another user uploaded a new version, `100.10.7`, which contains non-working code, with clear language that it intends to be a dependency confusion attack. It also does not contain working hacking code. The name has been prohibited on from use on PyPI on 2021-12-12.
Metadata
Created: 2025-03-17T17:49:49.186629Z
Modified: 2025-03-17T16:35:37Z
Source: https://osv-vulnerabilities
CWE IDs: N/A
Alternative ID: N/A
Finding: F138
Auto approve: 1