# setuptools <70.0.0 is vulnerable to CVE-2024-6345: package_index download functions allow remote code execution via crafted package URLs.

- **ID:** `python/setuptools-cve-2024-6345-remote-code`
- **Domain:** python
- **Category:** system_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

setuptools' package_index module uses `eval()` on untrusted download URLs, enabling RCE when installing from a malicious index.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## Workarounds

1. **** (98% success)
   ```
   pip install --upgrade 'setuptools>=70.0.0'
   ```
2. **** (90% success)
   ```
   pip install pip-audit && pip-audit
   ```

## Dead Ends

- **** — Keeps the vulnerable version in place and exposes the environment to RCE. (95% fail)
- **** — HTTPS does not protect against a malicious index that serves crafted URLs. (70% fail)
- **** — Caching is unrelated to the vulnerability. (98% fail)
