PyPI: setuptools

CVE-2013-1633

Safety vulnerability ID: SFTY-20130806-81952

Safety legacy ID: pyup.io-25809

Setuptools version 0.7 includes a fix for CVE-2013-1633: Easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Created at: Apr 30, 2026Updated at: Apr 30, 2026

Overview

Setuptools vulnerable to Man-in-the-middle attacks

Advisory

Setuptools version 0.7 includes a fix for CVE-2013-1633: Easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Affected Package

Affecting setuptools package, versions
<0.7

Also affects

---

How to Fix

Upgrade
setuptools
to
0.7.2
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more