# VAITP - Vulnerability Attack and Injection Tool for Python
# Select a vulnerable file from the explorer
Patched Python Code
# VAITP - Vulnerability Attack and Injection Tool for Python
# Select a patched file from the explorer
Search for CVE
#
CVE
Vulnerability
ODC
Category
Subcategory
Accessibility Scope
Details
Total vulnerabilities in the dataset (not showing ignored and non-python related vulnerabilties): 1612
9
CVE-2023-27043
Incorrect parsing of e-mail addresses in Python email module
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
Function
Input Validation and Sanitization
Insecure Parsing or Deserialization
Remote
5
CVE-2023-38898
Sensitive information exposure in _asyncio._swap_current_task
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component.
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
Legal Disclaimer
Welcome to VAITP! Before accessing the website, you must read and accept the following disclaimer:
This website provides access to uncensored AI models for educational purposes as part of Frรฉdรฉric Bogaerts PhD research project.
You are allowed to send a Python script along with a user prompt, and the AI model will respond with modifications based on your input.
The project is in a beta phase, and the models may provide unreliable answers.
Due to limited resources, you may experience bottlenecks, downtime, or slow responses.
You must not use this system for malicious purposes or to cause harm.
By clicking 'Accept', you acknowledge that you understand and agree to these terms.