PT-2024-40896 · Microsoft+2 · Windows+2

Published

2024-01-03

·

Updated

2024-01-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions gratient version 0.5
Description The issue concerns malicious code embedded in the library, which targets Windows platforms. This code is capable of harvesting information and credentials from the user's system and sending them to a remote server. Services that may be affected include Mullvad VPN and Telegram.
Recommendations For version 0.5, avoid using the gradient library until a clean version is available, and consider removing the current version to prevent potential data harvesting. As a temporary workaround, consider restricting access to sensitive information on systems where this library is used.

Related Identifiers

PYSEC-2024-1

Affected Products

Mullvad Vpn
Telegram
Windows