pypi package report

Is nicotine-plus safe?

1 known vulnerability, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
1.6%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-p4v2-r99v-wjc2, the advisory selected below

// advisories

GHSA-p4v2-r99v-wjc2

HIGHCVE-2021-45848

Denial of service (DoS) vulnerability in Nicotine+ starting with version 3.0.3 and prior to version 3.2.1 allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.

Affected
>= 3.0.3, < 3.2.1
Fixed in
3.2.1
Weakness
CWE-116
Published
2022-03-16
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 01:47 UTC. The most recent advisory here was published 2022-03-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is nicotine-plus safe? pypi package security report | CyberXYZ