CVE-2013-1633: Python Setuptools

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Affected products

  • Python Setuptools: up to and including 0.7b4; version 0.6.40 only; version 0.6.41 only; version 0.6.42 only; version 0.6.43 only; version 0.6.44 only; …

Published 2013-08-06. Last modified 2026-06-16.