pyinfra is vulnerable to Command Injection
84
High Risk
pyinfra turns declared operations and connector plumbing into shell snippets executed over SSH and related transports. User-controlled fragments were previously stitched into commands with insufficient quoting discipline, so shell metacharacters could change interpretation beyond the intended single argument boundary. The release routes untrusted fragments through structured quoting helpers such as QuoteString and StringCommand, tightens formatted command assembly, and adds regression coverage that metacharacter payloads stay quoted instead of executing.
You are affected if you are using a version that falls within the vulnerable range.
pyinfra is vulnerable to Command Injection in versions 0.1 - 3.7.
Upgrade the pyinfra library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant