---
id: CVE-2022-31313
aliases:
  - PYSEC-2022-43071
  - GHSA-6978-4w92-428p
title: >-
  api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in
  the request package.
summary: >-
  api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in
  the request package.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: api-res-py
product: api-res-py
ecosystem: pip
affected:
  - api-res-py <= 0.1
published: '2022-06-08'
updated: '2026-07-01'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2022-43071'
references:
  - url: 'https://github.com/rakeshrkz7/as_api_res/issues/1'
  - url: 'http://pypi.doubanio.com/simple/request'
  - url: 'https://pypi.org/project/api-res-py/'
  - url: 'https://github.com/advisories/GHSA-6978-4w92-428p'
tags:
  - osv
  - pip
epss: 0.01825
epssPercentile: 0.77865
ingestedAt: '2026-07-08T18:25:55.334Z'
---

## Overview

api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.

## Affected packages

- `api-res-py <= 0.1`

## Remediation

Refer to the advisory for the patched release.
