StackRadar

CVE-2023-5752

Medium

Advisory

Published 25 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
756
of 17,787 indexed, latest versions
Container images
786
deployed by those charts
Fix available
1 of 2
affected packages

Command Injection in pip when used with Mercurial

Carried by container images the latest versions of 756 of 17,787 indexed charts deploy, on 786 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+50 more23.3786
python-pipdeb23.0.1+dfsg-1no fix listed25
OSV records
GHSA-mq26-g339-26xfDEBIAN-CVE-2023-5752
Also known as
PYSEC-2023-228

Charts affected

756 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pip@23.0.1
23.3
hamzaarshad10/querypodpy:1.7154f38e8668e
pip@23.0.1
23.3
murtazashah46/helmfile:latest4d11726cf803
pip@23.0.1
23.3

Open the chart page →

13,197
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pip@22.3.1
23.3

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
23.3

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
pip@22.3.1
23.3

Open the chart page →

1,838
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

1,636

Container images carrying it

786 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
santisbon/speedtest:latest8ee3a1697227
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
pip@23.0.1
23.3
1
scrapinghub/splash:3.4.1a5f89bc84606
pip@9.0.1
23.3
1
seafileltd/seafile-mc:9.0.106693911bcc40
pip@20.0.2
23.3
1
seafileltd/seafile-mc:10.0.170628f29c663
pip@20.0.2
23.3
1
seafileltd/seafile-mc:9.0.97ac833196f60
pip@20.0.2
23.3
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pip@22.0.2
23.3
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pip@21.2.3
23.3
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
pip@21.2.4
23.3
1
seldonio/locust-core:0.81d0da98a2d76
pip@8.1.1
23.3
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
pip@19.3.1
23.3
1
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
pip@23.2.1
23.3
1
shaowenchen/ops-controller-manager:latest26da43bb5b66
pip@22.0.2
23.3
1
shaowenchen/ops-server:latest315444f703f4
pip@22.0.2
23.3
1
sharanalwar/redchef-backend:latest8d3cab80df49
pip@23.0.1
23.3
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
pip@23.0.1
23.3
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
pip@20.3.4
23.3
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
pip@20.0.2
23.3
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
pip@22.0.4
23.3
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
pip@22.0.4
23.3
1
socialmediamacroscope/classification_train:0.1.207477060bba8
pip@22.0.4
23.3
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
pip@22.0.4
23.3
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
pip@22.0.4
23.3
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
pip@22.0.4
23.3
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
pip@22.0.4
23.3
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
pip@22.0.4
23.3
1
socialmediamacroscope/collect_reddit_comment:0.1.219d3d26d53ee
pip@9.0.1
23.3
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
pip@23.0.1
23.3
1
socialmediamacroscope/image_crawler:0.1.2f508216be63c
pip@9.0.1
23.3
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
pip@23.0.1
23.3
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
pip@23.0.1
23.3
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
pip@22.0.4
23.3
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
pip@23.0.1
23.3
1
softonic/gar-exporter:0.2.1a64d6c0e0ae5
pip@20.2.4
23.3
1
softonic/mysql-backup:0.4.0d9487a8dd70f
pip@18.1
23.3
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
pip@20.0.2
23.3
1
speckle/speckle-monitor-deployment:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb2faf1508c1d3
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.20.2-branch.testing4.134160-9fad4b23c8fbe855665
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.20.6-branch.testing1.154030-9b09114738c77eb6f97
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.18.12-branch.testing3.88744-f55b34181335b40696a
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.19.2-branch.hotfix-2.19.1.124125-665e7e1b696ac5022ab
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.21.3-branch.testing5.219631-2153befcf72ad0f25fb
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.18.11-branch.testing2.88634-335d469d6790a97ad47
pip@23.0.1
23.3
1
speckle/speckle-monitor-deployment:2.17.14-branch.testing.72707.921a5f8ff1641ac3f1b
pip@23.0.1
23.3
1
sslhep/servicex_app:v1.8.51d12f943cec5
pip@23.0.1
23.3
1
sslhep/servicex_code_gen_atlas_xaod:v1.8.5e7aff7f97b89
pip@23.0.1
23.3
1
sslhep/servicex_code_gen_func_adl_uproot:v1.8.5b01b8ee966ed
pip@23.0.1
23.3
1
sslhep/servicex_code_gen_python:v1.8.50e4175a4e1eb
pip@23.0.1
23.3
1
sslhep/servicex_code_gen_raw_uproot:v1.8.5671980005c57
pip@23.0.1
23.3
1
sslhep/servicex_code_gen_topcp:v1.8.5596db2abdd09
pip@23.0.1
23.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.