CVE-2025-47273 is a path traversal vulnerability in the PackageIndex component of setuptools before version 78.1.1. Exploitation allows an attacker to write files to arbitrary filesystem locations accessible to the process running the Python code. Depending on the execution context, these writes may lead to remote code execution. Setuptools 78.1.1 fixes the vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains two standalone Python proof-of-concept exploits plus minimal documentation. It is not part of a larger exploit framework. The top-level README describes the repository as PoCs for two privilege-escalation related issues: CVE-2024-25081 in FontForge and CVE-2025-47273 in setuptools. Repository structure: - README.md: high-level description of both CVEs and their intended impact. - CVE-2024-25081/CVE-2024-25081.py: Python exploit that builds a malicious ZIP archive. - CVE-2025-47273/CVE-2025-47273.py: Python exploit/helper that generates SSH keys and serves an authorized_keys file over HTTP. - CVE-2025-47273/README.md: brief dependency note for the cryptography library. CVE-2024-25081 exploit details: - Accepts --lhost, --lport, and optional --zip. - Constructs a bash reverse shell command using /dev/tcp/<LHOST>/<LPORT>. - Base64-encodes the reverse shell and embeds it in a ZIP entry filename using shell substitution syntax: $(echo${IFS}'... '|base64${IFS}-d|bash). - Writes an empty file into the ZIP under that malicious filename. - The intended effect is command injection when a vulnerable FontForge workflow processes the ZIP and unsafely passes the filename to a shell. - Main capability: code execution as the user running FontForge, with a reverse shell back to the attacker. CVE-2025-47273 exploit details: - Accepts --lhost and --format, though only ed25519 and rsa are actually implemented in code despite argparse also listing ecdsa. - Generates an SSH keypair using the cryptography library. - Saves the private key to rootkey, the public key to rootkey.pub, and duplicates the public key into authorized_keys. - Starts a simple HTTP server on port 8000 and serves the authorized_keys file for any GET request. - The script itself does not perform the traversal/write against the target; instead, it prepares attacker-controlled content and hosting infrastructure for a vulnerable setuptools-based fetch/write path. The README indicates the operator should execute a script where setuptools is vulnerable and URL-encode the path. - Main capability: support for privilege escalation/persistence by planting an SSH public key into a privileged account's authorized_keys file, potentially enabling root SSH login if the vulnerable target writes the file into the correct location. Overall assessment: - These are real exploit PoCs rather than scanners or detection scripts. - The FontForge exploit is a direct weaponized file generator with a hardcoded reverse-shell pattern. - The setuptools exploit is more of an exploitation helper/primitive: it generates the key material and hosts it, but relies on a separate vulnerable workflow to fetch and write the file to a sensitive path. - Both scripts are operational but relatively simple, with limited error handling and no advanced automation.
This repository is a small, focused proof-of-concept for CVE-2025-47273 in PyPA setuptools.package_index. It contains one documentation file (README.md) and one Python script (server.py). The README explains the root cause: attacker-controlled URL path components are decoded and joined with a temporary directory using os.path.join(), allowing an absolute path such as /root/.ssh/authorized_keys to discard the intended tmpdir and become the final write destination. The exploit capability is arbitrary file write on the target system wherever the vulnerable process has permissions. The included operational PoC uses a malicious HTTP server to serve the attacker’s SSH public key from id_rsa.pub, then instructs the victim to call PackageIndex().download() with a crafted URL containing a percent-encoded absolute path. If executed with sufficient privileges, this overwrites /root/.ssh/authorized_keys and grants root SSH access using the matching private key. server.py is minimal: it starts an HTTP server on a user-supplied port (default 8000), binds to 0.0.0.0, and returns the contents of id_rsa.pub for any GET request. The repository is not part of a larger exploit framework. Overall, this is a real exploit PoC rather than a detector: it demonstrates network delivery of attacker-controlled content and local filesystem impact through path traversal in setuptools 78.1.0 and earlier; the README notes the issue is fixed in 78.1.1.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability flagged by Tenable's Echo local security check for python-3.11 and related packages, with setuptools also identified in the security-update title. The plugin rates it High severity but does not describe the vulnerability's mechanism or impact.
A path-traversal vulnerability in the setuptools PackageIndex component affecting installed setuptools packages on Rocky Linux 8.
A path traversal vulnerability in the setuptools PackageIndex component affecting installed setuptools packages on Rocky Linux 9 systems.
A path-traversal vulnerability in the setuptools PackageIndex component affecting installed setuptools packages on Rocky Linux 8 systems covered by CIQ advisory CRLSA-2025:11044.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.