StackRadar

CVE-2023-5752

Medium

Advisory

Published 25 Oct 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
756
of 17,787 indexed, latest versions
Container images
786
deployed by those charts
Fix available
1 of 2
affected packages

Command Injection in pip when used with Mercurial

Carried by container images the latest versions of 756 of 17,787 indexed charts deploy, on 786 images.

Affected packageAffected versionsFixed inImages
pippypi1.5.4, 8.1.1, 8.1.2, 9.0.0+50 more23.3786
python-pipdeb23.0.1+dfsg-1no fix listed25
OSV records
GHSA-mq26-g339-26xfDEBIAN-CVE-2023-5752
Also known as
PYSEC-2023-228

Charts affected

756 by stars
ChartLatestAffected imagesRadar Score
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
pip@23.0.1
23.3
hamzaarshad10/querypodpy:1.7154f38e8668e
pip@23.0.1
23.3
murtazashah46/helmfile:latest4d11726cf803
pip@23.0.1
23.3

Open the chart page →

13,197
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pip@22.3.1
23.3

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
pip@9.0.3
23.3

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
pip@22.3.1
23.3

Open the chart page →

1,838
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-5752.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
pip@21.2.4
23.3

Open the chart page →

1,636

Container images carrying it

786 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/crate:4.7.0c7984a05e15b
pip@9.0.3
23.3
1
library/python:3.8-alpine3d93b1f77efc
pip@23.0.1
23.3
1
library/python:3.1070c9cc675605
pip@23.0.1
23.3
1
library/python:3.8d41127070014
pip@23.0.1
23.3
1
library/python:3.9da5aee29682d
pip@23.0.1
23.3
1
librenms/librenms:22.4.14f1f3d667cc7
pip@22.0.4
23.3
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pip@22.1
23.3
1
linuxserver/beets:1.5.0e36d16f7341c
pip@21.3.1
23.3
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
pip@21.2.4
23.3
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pip@19.0.1
23.3
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pip@19.3.1
23.3
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
pip@21.1.1
23.3
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
pip@23.0.1
23.3
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pip@21.1.2
23.3
1
linuxserver/medusa:v0.3.9-ls340a5f5114128b
pip@19.2.3
23.3
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pip@19.3.1
23.3
1
linuxserver/yq:3.2.26f5b9586a93e
pip@23.2.1
23.3
1
lnbitsdocker/lnbits-legend:latest26fae6327477
pip@23.0.1
23.3
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
pip@23.0.1
23.3
1
lncm/specter-desktop:v0.10.4bca14d04397d
pip@20.2.3
23.3
1
localstack/localstack:3.19d278167f2b7
pip@23.2.1
23.3
1
logiqai/toolbox:2.0.155a574ec5b64
pip@18.1
23.3
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
pip@18.1
23.3
1
louislam/uptime-kuma:13d632903e6af
pip@18.1
23.3
1
louislam/uptime-kuma:1.23.1396510915e6be
pip@18.1
23.3
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
pip@18.1
23.3
1
louislam/uptime-kuma:1.18.5a84767d7934f
pip@18.1
23.3
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
pip@18.1
23.3
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
pip@21.2.4
23.3
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
pip@21.2.4
23.3
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pip@22.0.3
23.3
1
lsstsqre/kafkaaggregator:masterbe1b21060854
pip@21.0.1
23.3
1
lsstsqre/kafkaconnect:0.9.34143c7cd705e
pip@21.3.1
23.3
1
lsstsqre/narrativelog:0.1.0ce01de04ce21
pip@22.0.3
23.3
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
pip@20.0.2
23.3
1
lsstsqre/prepuller:latest19c2dfc4e4ff
pip@21.0.1
23.3
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
pip@21.0.1
23.3
1
lsstsqre/squash-api:0.5.34879415ec6ac
pip@20.3.2
23.3
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
pip@21.2.4
23.3
1
lsstsqre/wfdispatcher:lateste9feb99f524d
pip@21.0.1
23.3
1
makersquad/harp-proxy:0.8.1a40dd258c527
pip@23.0.1
python-pip@23.0.1+dfsg-1
23.3
no fix listed
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
pip@21.2.4
23.3
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pip@21.2.4
23.3
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pip@22.3.1
23.3
1
mediagis/nominatim:3.7c15e941485ef
pip@20.0.2
23.3
1
mediagis/nominatim:4.2d0eae7b51374
pip@22.0.2
23.3
1
mher/flower:2.051c3c3db5be3
pip@23.1.2
23.3
1
middlewareeng/middleware:0.3.1747d880812f1
pip@23.0.1
23.3
1
milesmcc/shynet:v0.13.1ba54f7797a6b
pip@22.0.4
23.3
1
milesmcc/shynet:v0.12.0e821e31140f7
pip@21.2.4
23.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.