ty is vulnerable to Use After Free
78
High Risk
ty's incremental analysis engine can access freed memory when it processes a specially crafted Python project, caused by a use-after-free in Salsa, the incremental computation library ty relies on. Opening such a project in an editor or running ty check --fix against it triggers the flaw without executing any of the project's Python code. The stale memory access can result in arbitrary code execution with the privileges of the user running ty. The fix upgrades ty to a Salsa release that resolves the use-after-free.
You are affected if you are using a version that falls within the vulnerable range and you use ty to analyze a Python project from an untrusted source.
ty is vulnerable to Use After Free in versions 0.0.1 - 0.0.83.
Upgrade the ty library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.