Intel

AIKIDO-2024-10539

pyngrok is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 16, 2024

40

Medium Risk

This Affects:

pythonpyngrok
0.1.2 - 7.1.6
Fixed in 7.2.0
Are you affected? Scan for Free

TL;DR

The pyngrok package versions up to 7.1.6 are no longer supported by the maintainer and will not receive further security updates. Users are strongly advised to upgrade to a supported version to ensure continued security and functionality.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pyngrok is vulnerable to Use of Unmaintained Third Party Components in versions 0.1.2 - 7.1.6.

How to fix this

Upgrade the pyngrok library to the patch version.