PatchSiren cyber security CVE debrief
CVE-2016-10075 Tqdm Project CVE debrief
CVE-2016-10075 is a high-severity local code execution issue in tqdm’s _version module. According to the CVE description and NVD record, vulnerable versions 4.4.1 and 4.10 can be abused when a crafted repository with a malicious git log is present in the current working directory, allowing arbitrary code execution by a local user context.
- Vendor
- Tqdm Project
- Product
- Tqdm
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-19
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-19
- Advisory updated
- 2026-05-13
Who should care
Administrators and developers who run tqdm 4.4.1 or 4.10 on multi-user systems, developer workstations, CI agents, or build environments should care most—especially if those environments may open or inspect untrusted repositories.
Technical summary
NVD classifies the issue with CVSS 3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and CWE-17. The vulnerable behavior is tied to tqdm._version and is triggered by malicious git log content in the current working directory, making this a local attack surface rather than a network-exposed one. The NVD CPE entries specifically list tqdm 4.4.1 and 4.10 as vulnerable.
Defensive priority
High. Treat this as urgent on any system that may process untrusted repositories or shared working directories, because successful exploitation can lead to full code execution with the privileges of the affected local user.
Recommended defensive actions
- Upgrade tqdm to a non-vulnerable release before using it in shared, developer, or automation environments.
- Remove or replace the specifically vulnerable versions 4.4.1 and 4.10 from golden images, dependency locks, and build caches.
- Avoid running affected tqdm versions in directories that can contain attacker-controlled or untrusted git repositories.
- Review scripts and CI jobs that import or initialize tqdm in repository workspaces, and constrain them to trusted inputs only.
- Verify downstream packages and environment images that vendor or pin tqdm, then redeploy after remediation.
Evidence notes
The supplied CVE description states that tqdm._version in versions 4.4.1 and 4.10 can execute arbitrary code via a crafted repo with a malicious git log in the current working directory. NVD lists the same affected versions in its CPE criteria and assigns CVSS 3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H with CWE-17. Public discussion is reflected in the Openwall oss-security thread dated 2016-12-28, and the CVE record was published on 2017-01-19.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10075 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10075
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10075 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10075
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/tqdm/tqdm/issues/328
[email protected] - Issue Tracking, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201807-01
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.