PyPI incidents
Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Malicious code in anthropic-sdk (PyPI)
Malicious code in anthropic-sdk (PyPI)
Malicious code in voxcpmtts3 (PyPI)
Malicious code in voxcpmtts3 (PyPI)
Malicious code in echogen (PyPI)
Malicious code in echogen (PyPI)
Malicious code in voxcpmkit (PyPI)
Malicious code in voxcpmkit (PyPI)
Malicious code in voxcpmintel (PyPI)
Malicious code in voxcpmintel (PyPI)
Malicious code in caoxiltts (PyPI)
Malicious code in caoxiltts (PyPI)
Malicious code in voxcpmruntime (PyPI)
Malicious code in voxcpmruntime (PyPI)
Malicious code in voxcpmui3 (PyPI)
Malicious code in voxcpmui3 (PyPI)
Malicious code in voxcpmui4 (PyPI)
Malicious code in voxcpmui4 (PyPI)
Malicious code in voxcpmeval (PyPI)
Malicious code in voxcpmeval (PyPI)
Malicious code in voxel-tts (PyPI)
Malicious code in voxel-tts (PyPI)
Malicious code in infrabench (PyPI)
Malicious code in infrabench (PyPI)
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
headroom-ai: before 0.35.0
Malicious code in voxeval (PyPI)
Malicious code in voxeval (PyPI)
Malicious code in dedh-devops-automation (PyPI)
Malicious code in dedh-devops-automation (PyPI)
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
vibe-trading-ai: 0.1.0 → 0.1.7
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
dulwich: before 1.2.9
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
dulwich: 0.23.1 → 1.2.8
Vibe-Trading file-read tools expose arbitrary server-readable files
Vibe-Trading file-read tools expose arbitrary server-readable files
vibe-trading-ai: 0.1.0 → 0.1.7
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
vibe-trading-ai: 0.1.0 → 0.1.7
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
dulwich: 0.24.0 → 1.2.8
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
dulwich: before 1.2.9
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
geopy: before 2.5.0
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
dulwich: 0.22.5 → 1.2.8
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
lightrag-hku: before 1.5.5
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
pyjwt: before 2.14.0
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
jupyterlab: 4.6.0 → 4.6.4
pypdf: Possible long runtimes when generating appearance streams
pypdf: Possible long runtimes when generating appearance streams
pypdf: before 6.19.0
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
open-webui: 0.10.0 → 0.11.1
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
vllm: before 0.28.0
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure
litellm: all versions
foreman-mcp-server Inserts Sensitive Information into Log File
foreman-mcp-server Inserts Sensitive Information into Log File
foreman-mcp-server: all versions
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
pyjwt: before 2.14.0
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
mcp-atlassian: before 0.22.0
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.9.0
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
open-webui: 0.9.0 → 0.11.1
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
mcp-atlassian: before 0.22.0
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
djust: before 1.0.7
Hugging Face Transformers downloads custom generation code before trust consent
Hugging Face Transformers downloads custom generation code before trust consent
transformers: ≥ 4.49.0
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
mcp-atlassian: before 0.22.0
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
mcp-atlassian: before 0.22.0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
jupyterlab: 4.6.0 → 4.6.4
djust has broken object-level access control (IDOR)
djust has broken object-level access control (IDOR)
djust: before 1.0.7
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui: 0.9.5 → 0.11.1
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
oauthlib: 0.6.1 → 4.0.0
MCP Atlassian: SSRF Protection Bypass
MCP Atlassian: SSRF Protection Bypass
mcp-atlassian: before 0.22.0
pypdf: Possible large memory usage when retrieving alphabetical page labels
pypdf: Possible large memory usage when retrieving alphabetical page labels
pypdf: before 6.19.0
pypdf: Possible long runtimes with large amount of embedded files
pypdf: Possible long runtimes with large amount of embedded files
pypdf: before 6.19.0
OpenStack Swift vulnerable to authenticated server-side request forgery
OpenStack Swift vulnerable to authenticated server-side request forgery
swift: before 2.37.2
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration
litellm: all versions
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
nautobot: 3.0.0 → 3.1.8
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
asyncssh: before 2.24.0
Home Assistant: XSS in Statistics Graph Card
Home Assistant: XSS in Statistics Graph Card
homeassistant: before 2026.7.0
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
compliance-trestle: before 3.12.4
pypdf: Possible long runtimes with large amount of embedded files
pypdf: Possible long runtimes with large amount of embedded files
pypdf: before 6.19.0
wlc may disclose API tokens to project-configured URLs
wlc may disclose API tokens to project-configured URLs
wlc: before 2.0.1
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
djust: before 1.0.7
urllib3: Chunked Deflate streaming can enter an infinite loop
urllib3: Chunked Deflate streaming can enter an infinite loop
urllib3: 2.6.2 → 2.8.0
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
pyjwt: ≥ 2.11.0
PyJWT accepts public JWK containers as HMAC secrets
PyJWT accepts public JWK containers as HMAC secrets
pyjwt: 2.13.0 → 2.14.0
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui: 0.7.0 → 0.11.1
sanic chunked trailer request smuggling allows hidden second request execution
sanic chunked trailer request smuggling allows hidden second request execution
sanic: before 24.12.1
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
crossbar: before 26.7.1
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui: before 0.11.1
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
lightrag-hku: before 1.5.5
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
lightrag-hku: before 1.5.5
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
mcp-atlassian: before 0.22.0
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
lightrag-hku: before 1.5.5
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
mysql-mcp-server: before 0.4.2
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
soupsieve: before 2.9.0
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
pyjwt: before 2.14.0
Malicious code in friendly-tools (PyPI)
Malicious code in friendly-tools (PyPI)
mcp-atlassian has an incomplete SSRF remediation
mcp-atlassian has an incomplete SSRF remediation
mcp-atlassian: before 0.22.0
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
lmdeploy: 0.9.1 → 0.10.2
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
vllm: before 0.24.0
virtualenv bash and fish activation scripts execute commands embedded in paths
virtualenv bash and fish activation scripts execute commands embedded in paths
virtualenv: before 21.7.13
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
mcp-atlassian: before 0.22.0
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
hpack: before 4.2.0
Malicious code in spo365-graph (PyPI)
Malicious code in spo365-graph (PyPI)
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
djust: before 1.0.7
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
urllib3: 1.10.3 → 2.8.0
pypdf: Possible large memory usage when retrieving Roman page labels
pypdf: Possible large memory usage when retrieving Roman page labels
pypdf: before 6.17.0
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
plone-app-portlets: 5.0.0 → 5.0.8
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
open-webui: 0.9.0 → 0.11.1
AnyIO process-pool workers can block indefinitely on undrained stderr
AnyIO process-pool workers can block indefinitely on undrained stderr
anyio: before 4.14.2
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
litellm: all versions
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
litellm: before 1.88.6
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
mcp-atlassian: before 0.22.0
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
jupyterlab: 4.0.0 → 4.5.11
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
social-auth-core: before 5.0.0
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
mcp-atlassian: before 0.22.0
LiteLLM: M2M JWT Handler Has Improper Authorization
LiteLLM: M2M JWT Handler Has Improper Authorization
litellm: all versions
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
decepticon: before 1.1.17
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
notebook: 7.5.0 → 7.6.3
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
zapros: before 0.14.0
PyJWT BOM Bypass
PyJWT BOM Bypass
pyjwt: 2.13.0 → 2.14.0
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
pypdf: before 6.18.1
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
opencve: before 3.0.0
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
social-auth-core: before 5.0.0
djust has an authorization bypass on the WebSocket/SSE mount path
djust has an authorization bypass on the WebSocket/SSE mount path
djust: before 1.0.7
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
lightrag-hku: before 1.5.5
pypdf: Possible large memory usage when parsing font data
pypdf: Possible large memory usage when parsing font data
pypdf: before 6.18.1
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
mcp-atlassian: before 0.22.0
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
open-webui: 0.9.0 → 0.11.1
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
mcp-atlassian: before 0.22.0
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
decepticon-sdk: before 1.1.17
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
nautobot: before 2.4.37
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
mcp-atlassian: before 0.22.0
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.11.1
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
esphome-device-builder: before 1.0.12
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
pypdf: before 6.18.1
pypdf: Possible large memory usage when parsing font data
pypdf: Possible large memory usage when parsing font data
pypdf: before 6.18.1
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui: 0.10.0 → 0.11.1
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
litellm: all versions
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
open-webui: 0.6.27 → 0.11.1
plone.app.dexterity has a Denial of Service due to excessive title or description length
plone.app.dexterity has a Denial of Service due to excessive title or description length
plone-app-dexterity: before 3.2.3
virtualenv: Command injection via --prompt in activate.bat (batch activator)
virtualenv: Command injection via --prompt in activate.bat (batch activator)
virtualenv: before 21.7.12
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
mcp-atlassian: before 0.22.0
social-auth-core has a Session Fixation issue
social-auth-core has a Session Fixation issue
social-auth-core: before 5.0.0
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
pypdf: before 6.18.0
pypdf: Possible long runtimes when generating appearance streams
pypdf: Possible long runtimes when generating appearance streams
pypdf: before 6.19.0
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
mcp-atlassian: before 0.22.0
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
mnemosyne-memory: before 3.10.1
pypdf: Possible large memory usage when retrieving alphabetical page labels
pypdf: Possible large memory usage when retrieving alphabetical page labels
pypdf: before 6.19.0
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
pypdf: before 6.18.1
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
mcp-atlassian: before 0.22.0
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
lmdeploy: 0.12.1 → 0.12.3
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
mcp-atlassian: before 0.22.0
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
picklescan: before 0.0.28
Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path
Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path
doris-mcp-server: before 0.6.1
PickleScan has multiple stdlib modules with direct RCE not in blocklist
PickleScan has multiple stdlib modules with direct RCE not in blocklist
picklescan: before 1.0.4
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui: 0.9.6 → 0.11.1
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
accesscontrol: before 7.4
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
anyio: 4.14.0 → 4.14.2
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
pyjwt: 2.13.0 → 2.14.0
LiteLLM: Admin Key Handler Has Improper Authorization
LiteLLM: Admin Key Handler Has Improper Authorization
litellm: all versions
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
social-auth-core: before 5.0.0
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
compliance-trestle: before 3.12.4
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
decepticon-core: before 1.1.17
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
restrictedpython: before 8.4
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
pyjwt: before 2.14.0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
jupyterlite-core: before 0.8.4
PyJWT: PyJWKClient follows redirects when fetching JWKS
PyJWT: PyJWKClient follows redirects when fetching JWKS
pyjwt: before 2.14.0
social-auth-core has an Improper Authentication issue
social-auth-core has an Improper Authentication issue
social-auth-core: before 5.0.0
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
litellm: all versions
Picklescan missing detection when calling built-in python library function timeit.timeit()
Picklescan missing detection when calling built-in python library function timeit.timeit()
picklescan: before 0.0.25
MPXJ: XXE Vulnerability in MerlinReader
MPXJ: XXE Vulnerability in MerlinReader
mpxj: 5.5.5 → 16.4.1
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
urllib3: 1.26.0 → 2.8.0
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
mpxj: 7.3.0 → 16.5.0
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
mcp-atlassian: before 0.22.0
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
pyjwt: 2.9.0 → 2.14.0
sentence-transformers local model loading bypasses trust_remote_code and executes custom Python
sentence-transformers local model loading bypasses trust_remote_code and executes custom Python
sentence-transformers: before 5.6.0
Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing
Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing
django: before 5.2.17
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
picklescan: before 0.0.29
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
mcp-atlassian: before 0.22.0
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
litellm: before 1.83.9
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
jupyter-server: before 2.21.0
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
soupsieve: before 2.9.0
pypdf: Possible large memory usage when retrieving Roman page labels
pypdf: Possible large memory usage when retrieving Roman page labels
pypdf: before 6.17.0
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
pyjwt: 2.13.0 → 2.14.0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
jupyterlab: 3.0.0 → 4.5.11
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
djust: before 1.0.7
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
oauthlib: 3.0.0 → 4.0.0
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui: 0.8.11 → 0.11.1
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
jupyterlite-core: 0.7.0 → 0.8.4
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
picklescan: before 0.0.33
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
pyjwt: 2.0.0a1 → 2.15.0
Home Assistant: mDNS Server-Side Request Forgery
Home Assistant: mDNS Server-Side Request Forgery
homeassistant: before 2026.2.3
Chainlit contains a session hijacking vulnerability
Chainlit contains a session hijacking vulnerability
chainlit: before 2.10.1
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
pypdf: before 6.18.1
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
lmdeploy: 0.9.2 → 0.16.0
LiteLLM: SSO Debug Flow Has Improper Authentication
LiteLLM: SSO Debug Flow Has Improper Authentication
litellm: all versions
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
djust: before 1.0.7
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
psd-tools: before 1.17.4
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
autobahn: before 26.7.1
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
streamlink: before 8.6.0
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
djust: before 1.0.7
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
djust: before 1.0.7
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
open-webui: 0.6.41 → 0.11.1
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
djust: before 1.0.7
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
mcp-atlassian: before 0.22.0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
jupyterlab: 4.5.0 → 4.5.11
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
mcp-atlassian: before 0.22.0
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
mcp-atlassian: before 0.22.0
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
zapros: before 0.14.0
LiteLLM: MCP Proxy Has Improper Authentication
LiteLLM: MCP Proxy Has Improper Authentication
litellm: before 1.84.0
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
pypdf: before 6.18.0
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
pyjwt: 2.4.0 → 2.14.0
Malicious code in shortneer (PyPI)
Malicious code in shortneer (PyPI)
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
jupyterlab: 4.6.0 → 4.6.4
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
mesop: before 1.3.4
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui: 0.10.0 → 0.11.1
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
djust: before 1.0.7
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
scbe-aethermoore: 4.0.2 → 4.2.1
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
djust: before 1.0.7
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
mcp-atlassian: before 0.22.0
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
anyio: before 4.14.2
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
mcp-atlassian: before 0.22.0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
jupyterlite: 0.7.0 → 0.8.4
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
picklescan: before 0.0.29
urllib3: Chunked Deflate streaming can enter an infinite loop
urllib3: Chunked Deflate streaming can enter an infinite loop
urllib3: 2.6.2 → 2.8.0
GitPython submodule update path traversal can write outside the repository
GitPython submodule update path traversal can write outside the repository
gitpython: before 3.1.62
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
tornado: before 6.5.9
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
tornado: before 6.5.9
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
urllib3: 1.10.3 → 2.8.0
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
gitpython: before 3.1.60
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
tornado: before 6.5.9
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
urllib3: 1.26.0 → 2.8.0
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
gitpython: before 3.1.60
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
gitpython: 3.1.59 → 3.1.60
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
virtualenv: before 21.7.11
Malicious code in cleanup-string (PyPI)
Malicious code in cleanup-string (PyPI)
Malicious code in bfox-build-utils (PyPI)
Malicious code in bfox-build-utils (PyPI)
Malicious code in beautifytext (PyPI)
Malicious code in beautifytext (PyPI)
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
pyjwt: before 2.14.0
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
pyjwt: 2.0.0a1 → 2.15.0
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
virtualenv: before 21.7.12
Malicious code in friendly-greeting-tools (PyPI)
Malicious code in friendly-greeting-tools (PyPI)
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
litellm: before 1.88.6
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
pyjwt: ≥ 2.11.0
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
pyjwt: before 2.14.0
PyJWT accepts public JWK containers as HMAC secrets
PyJWT accepts public JWK containers as HMAC secrets
pyjwt: 2.13.0 → 2.14.0
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
oauthlib: 0.6.1 → 4.0.0
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
pyjwt: 2.13.0 → 2.14.0
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
pyjwt: before 2.14.0
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
oauthlib: 3.0.0 → 4.0.0
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
pyjwt: before 2.14.0
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
pyjwt: 2.9.0 → 2.14.0
PyJWT: PyJWKClient follows redirects when fetching JWKS
PyJWT: PyJWKClient follows redirects when fetching JWKS
pyjwt: before 2.14.0
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
pyjwt: 2.13.0 → 2.14.0
PyJWT BOM Bypass
PyJWT BOM Bypass
pyjwt: 2.13.0 → 2.14.0
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
pyjwt: 2.4.0 → 2.14.0
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on Linux, '&' on Windows) are interpreted. If a victim loads and processes a crafted configuration fil
monai: before 1.6.0
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.
monai: before 1.6.1rc0
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC sc
monai: all versions
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.
monai: before 1.6.0
Malicious code in donutpromotion (PyPI)
Malicious code in donutpromotion (PyPI)
MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n
MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.
monai: before 1.6.0
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.
monai: before 1.5.2
Malicious code in metrio (PyPI)
Malicious code in metrio (PyPI)
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().
monai: before 1.6.1rc0
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
scbe-aethermoore: 4.0.2 → 4.2.1
Malicious code in my-private-pkg (PyPI)
Malicious code in my-private-pkg (PyPI)
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
social-auth-core: before 5.0.0
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
streamlink: before 8.6.0
Malicious code in prosocks (PyPI)
Malicious code in prosocks (PyPI)
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
social-auth-core: before 5.0.0
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
decepticon-core: before 1.1.17
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
compliance-trestle: before 3.12.4
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
social-auth-core: before 5.0.0
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
compliance-trestle: before 3.12.4
social-auth-core has an Improper Authentication issue
social-auth-core has an Improper Authentication issue
social-auth-core: before 5.0.0
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
hpack: before 4.2.0
social-auth-core has a Session Fixation issue
social-auth-core has a Session Fixation issue
social-auth-core: before 5.0.0
plone.app.dexterity has a Denial of Service due to excessive title or description length
plone.app.dexterity has a Denial of Service due to excessive title or description length
plone-app-dexterity: 5.0.0 → 5.0.1
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
zapros: before 0.14.0
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
mesop: before 1.3.4
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
zapros: before 0.14.0
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
plone-app-portlets: 7.0.0 → 7.0.2
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
mcp-atlassian: before 0.22.0
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
nautobot: before 2.4.37
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
autobahn: before 26.7.1
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
mcp-atlassian: before 0.22.0
Home Assistant: XSS in Statistics Graph Card
Home Assistant: XSS in Statistics Graph Card
homeassistant: before 2026.7.0
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
mcp-atlassian: before 0.22.0
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
nautobot: 3.0.0 → 3.1.8
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
mcp-atlassian: before 0.22.0
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
mcp-atlassian: before 0.22.0
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
mcp-atlassian: before 0.22.0
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
mcp-atlassian: before 0.22.0
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
mcp-atlassian: before 0.22.0
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
mcp-atlassian: before 0.22.0
MCP Atlassian: SSRF Protection Bypass
MCP Atlassian: SSRF Protection Bypass
mcp-atlassian: before 0.22.0
wlc may disclose API tokens to project-configured URLs
wlc may disclose API tokens to project-configured URLs
wlc: before 2.0.1
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
lightrag-hku: before 1.5.5
Home Assistant: mDNS Server-Side Request Forgery
Home Assistant: mDNS Server-Side Request Forgery
homeassistant: before 2026.2.3
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
mcp-atlassian: before 0.22.0
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
lightrag-hku: before 1.5.5
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
mcp-atlassian: before 0.22.0
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
mcp-atlassian: before 0.22.0
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
mcp-atlassian: before 0.22.0
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
mcp-atlassian: before 0.22.0
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
lightrag-hku: before 1.5.5
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
mcp-atlassian: before 0.22.0
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
lightrag-hku: before 1.5.5
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
psd-tools: before 1.17.4
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
lightrag-hku: before 1.5.5
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
mcp-atlassian: before 0.22.0
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
mcp-atlassian: before 0.22.0
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
mcp-atlassian: before 0.22.0
mcp-atlassian has an incomplete SSRF remediation
mcp-atlassian has an incomplete SSRF remediation
mcp-atlassian: before 0.22.0
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
mcp-atlassian: before 0.22.0
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
opencve: before 3.0.0
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.
vllm: before 0.30.0
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr
vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.
vllm: before 0.30.0
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.
vllm: before 0.30.0
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.
vllm: before 0.30.0
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.
vllm: before 0.30.0
Malicious code in urc (PyPI)
Malicious code in urc (PyPI)
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
mnemosyne-memory: before 3.10.1
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
anyio: before 4.14.2
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
anyio: 4.14.0 → 4.14.2
Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
virtualenv: before 21.7.12
AnyIO process-pool workers can block indefinitely on undrained stderr
AnyIO process-pool workers can block indefinitely on undrained stderr
anyio: before 4.14.2
LMDeploy has an SSRF bypass
LMDeploy has an SSRF bypass
lmdeploy: 0.12.3 → 0.15.0
virtualenv bash and fish activation scripts execute commands embedded in paths
virtualenv bash and fish activation scripts execute commands embedded in paths
virtualenv: before 21.7.13
Malicious code in py-venv-doctor (PyPI)
Malicious code in py-venv-doctor (PyPI)
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
lmdeploy: 0.9.2 → 0.16.0
Command injection via --prompt in activate.bat (batch activator)
Command injection via --prompt in activate.bat (batch activator)
virtualenv: before 21.7.12
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
lmdeploy: 0.12.1 → 0.12.3
Malicious code in requests-triwes (PyPI)
Malicious code in requests-triwes (PyPI)
Malicious code in marketing-mcp (PyPI)
Malicious code in marketing-mcp (PyPI)
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
soupsieve: before 2.9.0
djust: A template binding inherits a context safety grant it never earned (XSS)
djust: A template binding inherits a context safety grant it never earned (XSS)
djust: before 1.1.2
Malicious code in pyjstat-smooth (PyPI)
Malicious code in pyjstat-smooth (PyPI)
Malicious code in index-forum (PyPI)
Malicious code in index-forum (PyPI)
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
accesscontrol: before 7.4
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
jupyter-server: before 2.21.0
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
soupsieve: before 2.9.0
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
vllm: before 0.28.0
sanic chunked trailer request smuggling allows hidden second request execution
sanic chunked trailer request smuggling allows hidden second request execution
sanic: before 24.12.1
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
litellm: before 1.83.9
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
virtualenv: before 21.7.11
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
asyncssh: before 2.24.0
Malicious code in requests-auroras (PyPI)
Malicious code in requests-auroras (PyPI)
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
restrictedpython: before 8.4
Malicious code in requests-asetwe (PyPI)
Malicious code in requests-asetwe (PyPI)
Malicious code in aiosendletter (PyPI)
Malicious code in aiosendletter (PyPI)
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
djust: before 1.1.1
Malicious code in licloud (PyPI)
Malicious code in licloud (PyPI)
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
djust: before 1.0.7
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
djust: before 1.0.7
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
djust: before 1.0.7
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
djust: before 1.0.7
Malicious code in trongappy (PyPI)
Malicious code in trongappy (PyPI)
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
djust: before 1.0.7
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
djust: before 1.0.7
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
lmdeploy: 0.9.1 → 0.10.2
Malicious code in cli-anything-ai-market (PyPI)
Malicious code in cli-anything-ai-market (PyPI)
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
djust: before 1.0.7
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
djust: before 1.0.7
Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
vllm: before 0.24.0
Malicious code in praetorian-mind-rce-test-2026 (PyPI)
Malicious code in praetorian-mind-rce-test-2026 (PyPI)
Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectio
Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer — `dag_run_events_enabled` or `task_instance_events_enabled`, both disabled by default — build that client inside the scheduler process, so a user whose only privilege is editing Ai
apache-airflow-providers-apache-kafka: 1.15.0 → 2.0.0
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
djust: before 1.0.7
djust has broken object-level access control (IDOR)
djust has broken object-level access control (IDOR)
djust: before 1.0.7
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
djust: before 1.0.7
djust has an authorization bypass on the WebSocket/SSE mount path
djust has an authorization bypass on the WebSocket/SSE mount path
djust: before 1.0.7
Malicious code in faiss-cpu-avx512 (PyPI)
Malicious code in faiss-cpu-avx512 (PyPI)
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
esphome-device-builder: before 1.0.12
Malicious code in chroma-client (PyPI)
Malicious code in chroma-client (PyPI)
Malicious code in python-fork (PyPI)
Malicious code in python-fork (PyPI)
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores t
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.
vllm: before 0.28.0
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
mysql-mcp-server: before 0.4.2
Malicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
prowler-cloud: before 5.30.3
Malicious code in aitextkit-py (PyPI)
Malicious code in aitextkit-py (PyPI)
Malicious code in aitextutils-py (PyPI)
Malicious code in aitextutils-py (PyPI)
Malicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
Malicious code in platform-telemetry-client (PyPI)
Malicious code in platform-telemetry-client (PyPI)
Malicious code in pymem-win (PyPI)
Malicious code in pymem-win (PyPI)
Malicious code in web3-eth-account (PyPI)
Malicious code in web3-eth-account (PyPI)
Malicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
Malicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
Malicious code in eth-account-web3 (PyPI)
Malicious code in eth-account-web3 (PyPI)
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: before 0.117.2
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents: before 1.6.58
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-websocket: before 1.1.1
vLLM: Cross-User Data Leak Vulnerability
vLLM: Cross-User Data Leak Vulnerability
vllm: before 0.27.0
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm: before 1.83.7
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
apache-airflow: before 3.3.0
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql: before 1.1.1
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb: before 0.3.0
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools: before 1.15.1
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython: before 3.1.58
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui: 0.10.0 → 0.11.1
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
open-webui: 0.9.0 → 0.11.1
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh: before 2.23.1
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
open-webui: 0.9.0 → 0.11.1
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
lightning: before 1.6.0
eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
eml-parser: before 3.0.2
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier: 9.5.0 → 9.15.2
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
chromadb: ≥ 0.5.0
ChromaDB has a code injection vulnerability
ChromaDB has a code injection vulnerability
chromadb: ≥ 0.4.17
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui: before 0.11.1
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.11.1
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython: before 3.1.51
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core: before 1.3.4
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
open-webui: 0.9.0 → 0.11.1
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle: before 3.12.4
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents: before 1.6.58
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2: before 2.11.0
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: before 6.15.0
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit: 2.4.0rc0 → 2.12.0
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpx2: 2.6.0 → 2.10.0
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser: before 3.0.2
asteval has a Sandbox Escape via BaseException Subclasses
asteval has a Sandbox Escape via BaseException Subclasses
asteval: before 1.0.9
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
githacker: before 1.1.8
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
ironic: 17.0.0 → 29.0.6
Remote code execution in pytorch lightning
Remote code execution in pytorch lightning
pytorch-lightning: before 2.3.3
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder: before 1.0.10
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
icalendar: 7.1.0 → 7.1.3
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler: before 5.37.0
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents: before 1.6.58
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh: before 2.23.1
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust: before 1.0.4
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks: before 2.4.5
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service: before 9.1.0
Malicious code in pylever (PyPI)
Malicious code in pylever (PyPI)
PyTorch Lightning path traversal vulnerability
PyTorch Lightning path traversal vulnerability
lightning: before 2.4.0
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2: before 2.10.0
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy: before 2.17.0
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython: before 3.1.52
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
thrift: before 0.24.0
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython: before 3.1.59
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython: before 3.1.51
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
accelerate: all versions
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython: before 3.1.58
aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection
aiosmtplib: before 5.1.2
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui: 0.9.5 → 0.11.1
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2: before 2.12.0
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui: 0.7.0 → 0.11.1
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler-cloud: before 5.37.0
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2: before 2.11.0
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui: 0.8.0 → 0.9.0
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents: 0.12.12 → 1.6.58
Cognee allows non-superusers to overwrite global LLM configuration
Cognee allows non-superusers to overwrite global LLM configuration
cognee: before 1.5.0
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub: before 5.5.0
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonai: 3.9.26 → 4.6.58
PyTorch Lightning denial of service vulnerability
PyTorch Lightning denial of service vulnerability
lightning: all versions
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
open-webui: 0.10.0 → 0.11.1
kas Persistently Disables SSH Host Key Checking
kas Persistently Disables SSH Host Key Checking
kas: before 5.4
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonai: 4.6.34 → 4.6.58
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit: 2.4.0rc0 → 2.12.0
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui: 0.10.0 → 0.11.1
plone.app.event vulnerable to denial of service via iCalendar import
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event: before 5.2.4
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
thrift: before 0.24.0
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: before 0.10.0
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
lightning: all versions
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune: 3.3.0 → 3.3.3
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-store-mongodb: before 0.4.0
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui: 0.9.6 → 0.11.1
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
open-webui: 0.6.27 → 0.11.1
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
gitpython: before 3.1.58
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
thrift: before 0.24.0
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent: before 0.3.0
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
keras: before 3.15.0
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser: before 3.0.2
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai: before 4.6.58
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
chromadb: ≥ 0.4.17
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui: 0.8.11 → 0.11.1
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai: before 4.6.58
Compromise of PyTorch Lightning PyPi Package Versions
Compromise of PyTorch Lightning PyPi Package Versions
lightning: 2.6.2 → 2.6.4
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk: before 3.10.3
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython: before 3.1.58
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
open-webui: 0.6.41 → 0.11.1
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai: before 4.6.58
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui: 0.9.5 → 0.11.1
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
justhtml: before 1.10.0
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
nltk: 3.10.0 → 3.10.3
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai: before 4.6.58
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
open-webui: 0.5.0 → 0.11.1
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai: before 4.6.58
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: before 1.6.58
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents: 1.5.128 → 1.6.58
OpenHarness remote resume commands expose other users' saved session snapshots
OpenHarness remote resume commands expose other users' saved session snapshots
openharness-ai: all versions
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
nltk: before 3.10.1
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai: before 4.6.58
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: before 6.16.1
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk: before 3.10.3
OpenHarness remote project-context commands allow persistent prompt poisoning
OpenHarness remote project-context commands allow persistent prompt poisoning
openharness-ai: all versions
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui: 0.10.0 → 0.11.1
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent: before 0.3.0
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
lightning: before 1.6.0
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2: 2.5.0 → 2.10.0
Material for MkDocs: DOM XSS in search suggestions via query parameter
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material: 7.2.0 → 9.7.7
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: before 0.10.0
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonai: before 4.6.58
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
pytorch-lightning: before 2.3.3
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway: before 1.0.2
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
praisonai: before 4.6.58
MLflow AI Gateway permits SSRF through an unvalidated api_base
MLflow AI Gateway permits SSRF through an unvalidated api_base
mlflow: ≥ 3.13.0
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk: before 3.10.3
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent: before 0.3.0
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonai: before 4.6.58
ONNX: TOCTOU arbitrary file read/write in save_external_dat
ONNX: TOCTOU arbitrary file read/write in save_external_dat
onnx: before 1.21.0
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent: before 0.3.0
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai: before 4.6.58
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin: before 1.14.0
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: before 1.6.58
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core: ≥ 2.0.0
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
sqladmin: before 0.27.1
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed: before 5.1.2
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents: before 1.6.58
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonai: before 4.6.58
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
snowflake-sqlalchemy: 1.1.6 → 1.11.0
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: before 6.16.1
Malicious code in lucy-python-script-2030 (PyPI)
Malicious code in lucy-python-script-2030 (PyPI)
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego: before 0.6.2
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy-mini: before 1.8.2
PyOD persistence.load deserializes untrusted artifacts before validation
PyOD persistence.load deserializes untrusted artifacts before validation
pyod: 3.5.0 → 3.6.2
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets: before 5.0.8
Snowflake Connector for Python improperly verifies TLS hostnames
Snowflake Connector for Python improperly verifies TLS hostnames
snowflake-connector-python: before 3.18.1
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference: before 2.7.0
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp: before 0.2.1
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
transformers: before 5.10.0
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm: 0.21.0 → 0.26.0
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm: before 0.26.0
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: before 6.16.0
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint: before 70.0
RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython: before 8.3
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm: before 0.26.0
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: before 0.6.0
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob: before 1.8.11
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin: before 0.16.1
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm: before 0.26.0
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm: before 0.26.0
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate: before 2026.7
WsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
wsgidav: before 4.3.5
Windows ML CLI: CORS misconfig enables localhost RCE
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli: before 0.4.0
Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
wagtail: before 7.0.9
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate: before 2026.7
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado: before 6.5.8
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: 0.4.7 → 0.24.0
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
githacker: before 1.1.8
Malicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
open-webui: 0.10.0 → 0.11.1
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
open-webui: 0.5.0 → 0.11.1
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrar
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
gitpython: before 3.1.60
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
esphome-device-builder: before 1.0.10
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
sqladmin: before 0.27.1
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that pro
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.
gitpython: before 3.1.60
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
gitpython: before 3.1.60
Malicious code in websetup (PyPI)
Malicious code in websetup (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint Has Server-Side Request Forgery (SSRF)
weasyprint: before 70.0
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
open-webui: 0.9.5 → 0.11.1
Windows ML CLI: CORS misconfig enables localhost RCE
Windows ML CLI: CORS misconfig enables localhost RCE
winml-cli: before 0.4.0
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
httpx2: before 2.11.0
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
httpcore2: before 2.10.0
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
nltk: before 3.10.0
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
nltk: before 3.9.3
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
nltk: before 3.10.0
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
nltk: before 3.9.4
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
nltk: before 3.10.3
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
nltk: before 3.10.0
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
nltk: 3.10.0 → 3.10.2
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
nltk: before 3.10.3
NLTK: Corpus Reader Sandbox Bypass
NLTK: Corpus Reader Sandbox Bypass
nltk: before 3.10.3
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
nltk: before 3.10.0
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
prowler: before 5.37.0
NLTK: Allowlisted pickle loaders still permit code execution in current source
NLTK: Allowlisted pickle loaders still permit code execution in current source
nltk: before 3.10.3
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
gitpython: before 3.1.59
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
nltk: before 3.10.3
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
gitpython: before 3.1.59
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
nltk: 3.10.0 → 3.10.2
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
nltk: before 3.10.0
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
nltk: before 3.10.3
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
httpx2: before 2.11.0
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
nltk: before 3.10.3
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
httpx2: 2.5.0 → 2.10.0
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()
gitpython: before 3.1.59
vLLM: Cross-User Data Leak Vulnerability
vLLM: Cross-User Data Leak Vulnerability
vllm: before 0.27.0
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
gitpython: before 3.1.59
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
vllm: before 0.26.0
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
gitpython: before 3.1.59
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
httpx2: before 2.12.0
Malicious code in cv-train (PyPI)
Malicious code in cv-train (PyPI)
Malicious code in telegram-helper (PyPI)
Malicious code in telegram-helper (PyPI)
Malicious code in minecraftmodes (PyPI)
Malicious code in minecraftmodes (PyPI)
Malicious code in dac-tools (PyPI)
Malicious code in dac-tools (PyPI)
Malicious code in trongridew (PyPI)
Malicious code in trongridew (PyPI)
Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit
Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit
local-operator: before 0.47.5
Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator
Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator
local-operator: before 0.47.5
Malicious code in dbt-sa-cli (PyPI)
Malicious code in dbt-sa-cli (PyPI)
Malicious code in proxycer (PyPI)
Malicious code in proxycer (PyPI)
Malicious code in astlsi (PyPI)
Malicious code in astlsi (PyPI)
Malicious code in tpu-raiden-jax (PyPI)
Malicious code in tpu-raiden-jax (PyPI)
Malicious code in olympuslib (PyPI)
Malicious code in olympuslib (PyPI)
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm: before 0.26.0
Malicious code in chartkit-core (PyPI)
Malicious code in chartkit-core (PyPI)
Malicious code in qoeoe (PyPI)
Malicious code in qoeoe (PyPI)
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm: before 0.26.0
Malicious code in timeweave (PyPI)
Malicious code in timeweave (PyPI)
Malicious code in houdus (PyPI)
Malicious code in houdus (PyPI)
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm: 0.21.0 → 0.26.0
Malicious code in pymaas (PyPI)
Malicious code in pymaas (PyPI)
Malicious code in tsshare (PyPI)
Malicious code in tsshare (PyPI)
tsshare: all versions
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm: before 0.26.0
Malicious code in metricboxlite (PyPI)
Malicious code in metricboxlite (PyPI)
Malicious code in env-validator-tool (PyPI)
Malicious code in env-validator-tool (PyPI)
Malicious code in 0requests (PyPI)
Malicious code in 0requests (PyPI)
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: Server-Side Request Forgery in the URL-based partitioning
unstructured: 0.4.7 → 0.24.0
Malicious code in py-2equests (PyPI)
Malicious code in py-2equests (PyPI)
Malicious code in py-0requests (PyPI)
Malicious code in py-0requests (PyPI)
Material for MkDocs: DOM XSS in search suggestions via query parameter
Material for MkDocs: DOM XSS in search suggestions via query parameter
mkdocs-material: 7.2.0 → 9.7.7
Malicious code in uvhttp-custom (PyPI)
Malicious code in uvhttp-custom (PyPI)
Malicious code in telemetry-helper (PyPI)
Malicious code in telemetry-helper (PyPI)
Malicious code in trongridi (PyPI)
Malicious code in trongridi (PyPI)
Malicious code in asti (PyPI)
Malicious code in asti (PyPI)
Malicious code in company-sdk (PyPI)
Malicious code in company-sdk (PyPI)
Malicious code in py-1requests (PyPI)
Malicious code in py-1requests (PyPI)
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
banks: before 2.4.5
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input
nltk: before 3.10.3
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
nltk: before 3.10.0
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
mistune: 3.3.0 → 3.3.3
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
omnigent: before 0.3.0
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
omnigent: before 0.3.0
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
nltk: before 3.10.3
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
nltk: all versions
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
scrapy: before 2.17
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat
There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web
pyspark: 3.0.0 → 3.5.8
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
omnigent: before 0.3.0
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
tornado: before 6.5.8
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'
nltk: before 3.10.3
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
nltk: before 3.10.3
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
pypdf: before 6.15.0
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars
nltk: before 3.10.3
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
nltk: before 3.10.0
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
omnigent: before 0.3.0
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
sqlparse: before 0.6.0
Malicious code in tallyboxlite (PyPI)
Malicious code in tallyboxlite (PyPI)
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
mlflow: 2.1.0 → 3.15.0
Malicious code in gcphelpit (PyPI)
Malicious code in gcphelpit (PyPI)
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: Possible infinite loop for TreeObject.insert_child
pypdf: before 6.16.0
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: Possible long runtimes/large memory usage when retrieving outlines
pypdf: before 6.16.1
Malicious code in syswatch (PyPI)
Malicious code in syswatch (PyPI)
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
pypdf: before 6.16.1
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
nltk: before 3.10.3
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
nltk: before 3.10.3
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework: before 3.17.2
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework: before 3.17.2
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
tornado: before 6.5.8
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
tornado: 6.5.5 → 6.5.8
Hugging Face Transformers downloads custom generation code before trust consent
Hugging Face Transformers downloads custom generation code before trust consent
transformers: ≥ 4.49.0
Malicious code in pyservercheck (PyPI)
Malicious code in pyservercheck (PyPI)
Malicious code in trongridor (PyPI)
Malicious code in trongridor (PyPI)
Malicious code in tronlinker (PyPI)
Malicious code in tronlinker (PyPI)
Malicious code in auth-app-streamlit (PyPI)
Malicious code in auth-app-streamlit (PyPI)
Malicious code in flask-header-guard (PyPI)
Malicious code in flask-header-guard (PyPI)
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets: 7.0.0 → 7.0.2
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin: before 1.14.0
Malicious code in pygame-renderkit (PyPI)
Malicious code in pygame-renderkit (PyPI)
RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython: before 8.3
Malicious code in yamlformat-tools (PyPI)
Malicious code in yamlformat-tools (PyPI)
Malicious code in yaml-report-formatter (PyPI)
Malicious code in yaml-report-formatter (PyPI)
WsgiDAV MySQL provider has a blind SQL injection
WsgiDAV MySQL provider has a blind SQL injection
wsgidav: before 4.3.5
Malicious code in yamlformatter-utils (PyPI)
Malicious code in yamlformatter-utils (PyPI)
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle: before 3.12.4
AIIR verification and policy gates could report success without enforcing the control (fail-open)
AIIR verification and policy gates could report success without enforcing the control (fail-open)
aiir: before 1.7.0
Malicious code in calcboxlite (PyPI)
Malicious code in calcboxlite (PyPI)
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate: before 2026.7
plone.app.event vulnerable to denial of service via iCalendar import
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event: before 5.2.4
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego: before 0.6.2
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate: before 2026.7
Malicious code in sap-quarterly-report (PyPI)
Malicious code in sap-quarterly-report (PyPI)
Malicious code in flyteplugins-redis (PyPI)
Malicious code in flyteplugins-redis (PyPI)
Malicious code in decoris (PyPI)
Malicious code in decoris (PyPI)
Malicious code in mathkitlite (PyPI)
Malicious code in mathkitlite (PyPI)
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.
openssl-encrypt: before 1.4.9
Malicious code in flyteplugins-agento11y (PyPI)
Malicious code in flyteplugins-agento11y (PyPI)
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.
nltk: before 3.10.3
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
nltk: before 3.10.3
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.
openssl-encrypt: before 1.4.9
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causin
nltk: before 3.10.3
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
nltk: before 3.10.3
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
openssl-encrypt: before 1.4.9
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext password is written to stderr. Anyone with access to that output (terminal scrollback, merged 2>&1 output,
openssl-encrypt: before 1.4.9
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main password. Any local user can read the steganography password from /proc/<pid>/cmdline for the lifetime of the subprocess. Fixed in 1.4.9.
openssl-encrypt: before 1.4.9
aiosmtplib: STARTTLS response injection
aiosmtplib: STARTTLS response injection
aiosmtplib: before 5.1.2
Malicious code in ekx-report-utils (PyPI)
Malicious code in ekx-report-utils (PyPI)
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.
openssl-encrypt: before 1.4.9
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a result the token is printed in cleartext to stderr under --debug (even without --unsafe-show-secrets), persisting the credential in logs and terminal history. Fixed in 1.4.9.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.
openssl-encrypt: before 1.4.9
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm: before 1.83.7
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the
openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().
openssl-encrypt: before 1.4.9
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords.
openssl-encrypt: before 1.4.9
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.
nltk: before 3.10.3
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
netron: before 9.1.3
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.
openssl-encrypt: before 1.4.9
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
netron: before 9.1.3
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob: before 1.8.11
Malicious code in flyteplugins-nsight (PyPI)
Malicious code in flyteplugins-nsight (PyPI)
Malicious code in flyteplugins-echo (PyPI)
Malicious code in flyteplugins-echo (PyPI)
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.
openssl-encrypt: before 1.4.9
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.
netron: before 9.1.3
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.
nltk: before 3.10.0
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing i
nltk: before 3.10.3
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core: ≥ 2.0.0
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh: before 2.23.1
Malicious code in bigquery-agent-analytics-tracing (PyPI)
Malicious code in bigquery-agent-analytics-tracing (PyPI)
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin: before 0.16.1
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
openwisp-ipam: before 1.2.1
Malicious code in syntaxerror-package-12345 (PyPI)
Malicious code in syntaxerror-package-12345 (PyPI)
Malicious code in rce-test (PyPI)
Malicious code in rce-test (PyPI)
kas Persistently Disables SSH Host Key Checking
kas Persistently Disables SSH Host Key Checking
kas: before 5.4
Malicious code in trongridet (PyPI)
Malicious code in trongridet (PyPI)
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh: before 2.23.1
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
pantheon-agents: 0.6.1 → 0.6.4
Malicious code in 0xfighter3 (PyPI)
Malicious code in 0xfighter3 (PyPI)
Malicious code in pybitjs (PyPI)
Malicious code in pybitjs (PyPI)
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust: before 1.0.4
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy-mini: before 1.8.2
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql: before 1.1.1
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server: before 0.117.2
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.
nltk: before 3.10.3
icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
icalendar: 7.1.0 → 7.1.3
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonai: before 4.6.58
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed: before 5.1.2
vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod
vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.
vllm: before 0.27.0
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonai: before 4.6.58
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code wit
nltk: before 3.10.0
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attack
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.
nltk: before 3.10.3
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an
nltk: before 3.10.3
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.
nltk: before 3.10.3
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().
nltk: before 3.10.3
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai: before 4.6.58
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
uff: all versions
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents: 1.5.128 → 1.6.58
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents: before 1.6.58
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents: before 1.6.58
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonai: 4.6.34 → 4.6.58
Malicious code in python-walletlibr-v (PyPI)
Malicious code in python-walletlibr-v (PyPI)
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http: before 1.1.4
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway: before 1.0.0
Malicious code in minecraft-ytreceiver (PyPI)
Malicious code in minecraft-ytreceiver (PyPI)
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub: before 5.5.0
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http: before 1.1.4
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai: before 4.6.58
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: before 1.6.58
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser: before 3.0.2
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit: 2.4.0rc0 → 2.12.0
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai: before 4.6.58
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.
nltk: before 3.10.3
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai: before 4.6.58
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents: before 1.6.58
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: before 1.6.58
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonai: before 4.6.58
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai: before 4.6.58
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents: before 1.6.58
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit: 2.4.0rc0 → 2.12.0
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai: before 4.6.58
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp: before 0.2.1
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
praisonai: before 4.6.58
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser: before 3.0.2
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents: 0.12.12 → 1.6.58
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai: before 4.6.58
eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
eml-parser: before 3.0.2
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms: before 5.0.8
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway: before 1.0.2
Malicious code in multyproccess (PyPI)
Malicious code in multyproccess (PyPI)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms: before 5.0.8
Malicious code in msrcpoc (PyPI)
Malicious code in msrcpoc (PyPI)
Malicious code in py-devoli-common (PyPI)
Malicious code in py-devoli-common (PyPI)
Malicious code in envprovision (PyPI)
Malicious code in envprovision (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in cryptgraphy (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
Malicious code in mlflow-otel-instrumentor (PyPI)
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
nltk: before 3.10.0
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebin
nltk: before 3.10.0
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.
nltk: before 3.9.4
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
nltk: before 3.10.0
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.
nltk: before 3.9.3
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.
nltk: before 3.10.0
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.
nltk: before 3.9.4
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
nltk: before 3.10.0
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
nltk: 3.10.0 → 3.10.2
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c
NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who contro
nltk: 3.9.4 → 3.10.3
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
nltk: 3.10.0 → 3.10.3
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
nltk: 3.9.4 → 3.10.3
Malicious code in scrambleeeer (PyPI)
Malicious code in scrambleeeer (PyPI)
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core: before 1.3.4
Malicious code in scrambleeer (PyPI)
Malicious code in scrambleeer (PyPI)
Malicious code in requests-crypt (PyPI)
Malicious code in requests-crypt (PyPI)
Malicious code in boto4 (PyPI)
Malicious code in boto4 (PyPI)
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference: before 2.7.0
Malicious code in reqcrypts (PyPI)
Malicious code in reqcrypts (PyPI)
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
nltk: before 3.10.1
django CMS: Structure endpoint bypasses page-view permission
django CMS: Structure endpoint bypasses page-view permission
django-cms: before 5.0.8
asteval has a Sandbox Escape via BaseException Subclasses
asteval has a Sandbox Escape via BaseException Subclasses
asteval: before 1.0.9
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms: before 5.0.9
Wagtail: Improper restriction handling on Pages admin API
Wagtail: Improper restriction handling on Pages admin API
wagtail: before 7.0.9
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
asteval: before 1.0.9
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms: before 5.0.8
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node: before 0.9.0a11
Wagtail: Reflected XSS in dynamic image URL generator view
Wagtail: Reflected XSS in dynamic image URL generator view
wagtail: 7.3 → 7.3.3
Wagtail: Improper permission handling in image preview
Wagtail: Improper permission handling in image preview
wagtail: before 7.0.8
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
zoo-kcl: before 0.3.153
Wagtail: Improper restriction handling on Page translation API endpoint
Wagtail: Improper restriction handling on Page translation API endpoint
wagtail: before 7.0.9
Wagtail: Denial of service via unbounded filter specs in the image preview
Wagtail: Denial of service via unbounded filter specs in the image preview
wagtail: before 7.0.8
Wagtail: Pages translations can be created without page permissions when using simple_translation
Wagtail: Pages translations can be created without page permissions when using simple_translation
wagtail: before 7.0.8
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
zoo-kcl: before 0.3.129
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
wagtail: before 7.0.8
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
wagtail: before 7.0.9
Wagtail: Improper permission handling when copying snippets
Wagtail: Improper permission handling when copying snippets
wagtail: before 7.0.9
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms: before 5.0.9
Wagtail: Identification of documents by SHA1 hash
Wagtail: Identification of documents by SHA1 hash
wagtail: before 7.0.9
django CMS: Stored XSS in edit-mode plugin exception rendering
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms: 5.0.8 → 5.0.9
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb: before 0.3.0
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier: 9.5.0 → 9.15.2
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api: before 0.10.0
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api: before 0.10.0
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: before 3.15.0
Malicious code in reqcrypt-dev (PyPI)
Malicious code in reqcrypt-dev (PyPI)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
homeassistant: before 2026.6.0
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
mcp-server-kubernetes: before 3.9.0
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: all versions
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
SGLang is Vulnerable to DoS via the data_hash Function
SGLang is Vulnerable to DoS via the data_hash Function
sglang: all versions
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
libp2p: all versions
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: before 0.22.0
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
jupyterlab: 3.3.0 → 4.5.10
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
jupyterlab: before 4.5.10
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens: before 1.2.3
MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
mlflow: 2.14.0rc0 → 3.13.0rc0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai: 1.65.0 → 1.106.0
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
geolens-cli: before 1.2.3
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
jupyterlab: 4.5.0 → 4.5.10
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
Malicious code in libasync (PyPI)
Malicious code in libasync (PyPI)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
geolens: before 1.2.4
Malicious code in rc4-secure (PyPI)
Malicious code in rc4-secure (PyPI)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service: before 9.1.0
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
lemur: before 1.9.3
MobSF's CSRF checks not enforced after Django migration
MobSF's CSRF checks not enforced after Django migration
mobsf: before 4.5.1
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
resdata: before 6.2.9
surfio has an out-of-bounds read
surfio has an out-of-bounds read
surfio: before 0.0.19
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
mobsf: before 4.5.1
MobSF has SSRF port restriction bypass in assetlinks_check
MobSF has SSRF port restriction bypass in assetlinks_check
mobsf: before 4.5.1
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
lemur: before 1.9.3
devpi-server may leak database contents
devpi-server may leak database contents
devpi-server: before 6.20.2
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
lemur: before 1.9.3
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
lemur: 0.5.0 → 1.9.3
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
lemur: before 1.9.3
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
lemur: before 1.9.3
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
linuxfabrik-lib: before 6.1.0
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
lemur: before 1.9.3
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
mobsf: before 4.5.1
Copyparty vulnerable to file/dirkey confusion
Copyparty vulnerable to file/dirkey confusion
copyparty: before 1.20.17
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
lemur: before 1.9.3
MONAI vulnerable to OS command injection
MONAI vulnerable to OS command injection
monai: before 1.6.0
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
monai: before 1.6.0
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
monai: before 1.6.0
Malicious code in deepface-weight (PyPI)
Malicious code in deepface-weight (PyPI)
Malicious code in deepface-weights (PyPI)
Malicious code in deepface-weights (PyPI)
Malicious code in reqcrypt (PyPI)
Malicious code in reqcrypt (PyPI)
Malicious code in httpz-requests (PyPI)
Malicious code in httpz-requests (PyPI)
Malicious code in infogram-bot (PyPI)
Malicious code in infogram-bot (PyPI)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
sqlparse: before 0.6.0
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.
openssl-encrypt: before 1.4.0
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
openssl-encrypt: before 1.4.0
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recover
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
openssl-encrypt: before 1.4.0
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
sqlparse: before 0.6.0
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
openssl-encrypt: before 1.4.0
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost.
openssl-encrypt: before 1.4.6
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
atomic-agents-stack: before 1.1.0
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hs
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to
openssl-encrypt: before 1.4.7
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: Quadratic O(n²) DoS in group_comments
sqlparse: before 0.6.0
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
atomic-agents-stack: before 1.1.0
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
glances: before 4.5.6
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
glances: before 4.5.6
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
glances: before 4.5.6
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
glances: 4.5.2 → 4.5.6
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
glances: before 4.5.6
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
mlflow: 3.3.0 → 3.15.0
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
openssl-encrypt: before 1.4.0
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
sqlparse: before 0.6.0
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.
openssl-encrypt: before 1.4.0
Malicious code in kb-ai (PyPI)
Malicious code in kb-ai (PyPI)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
mcp-contextforge-gateway: before 1.0.3
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: before 1.1.0
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.
gitpython: before 3.1.55
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing.
gitpython: before 3.1.56
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.
gitpython: before 3.1.57
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.
gitpython: before 3.1.54
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
gitpython: before 3.1.57
vLLM: Completion prompt lists fan out into unbounded engine requests
vLLM: Completion prompt lists fan out into unbounded engine requests
vllm: 0.19.0 → 0.26.0
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.
gitpython: before 3.1.54
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
pydantic-ai-slim: 1.65.0 → 1.106.0
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
nltk: before 3.10.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle: before 4.1.0
Apache Airflow Task SDK fails to mask list-shaped JSON Variables
Apache Airflow Task SDK fails to mask list-shaped JSON Variables
apache-airflow: before 3.3.1
Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass
Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass
apache-airflow: before 3.3.1
Apache Airflow Variables UI fails to mask sensitive values in deeply nested iterables
Apache Airflow Variables UI fails to mask sensitive values in deeply nested iterables
apache-airflow: before 3.3.1
Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs
Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se
apache-airflow: before 3.3.1
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: Stored XSS in the HTML export via unescaped dataset title
tablib: before 3.10.0
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext
apache-airflow: before 3.3.1
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n
apache-airflow: before 3.3.1
Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler
Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore
apache-airflow: before 3.3.1
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
stata-mcp: before 1.19.0
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
ansible-jailexec: before 2.0.0
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus
apache-airflow-providers-google: before 22.3.0
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m
apache-airflow: before 3.3.1
Apache Airflow Config API exposes team-scoped sensitive configuration values
Apache Airflow Config API exposes team-scoped sensitive configuration values
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option na
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulte
apache-airflow: before 3.3.1
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgr
apache-airflow: before 3.3.1
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
apache-airflow: before 3.3.1
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. T
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat
apache-airflow: before 3.3.1
Apache Airflow exception-node deserialization permits arbitrary callable execution
Apache Airflow exception-node deserialization permits arbitrary callable execution
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow environment-variable secrets backend permits cross-team credential use
Apache Airflow environment-variable secrets backend permits cross-team credential use
apache-airflow: before 3.3.1
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce
apache-airflow: 3.3.0 → 3.3.1
Apache Airflow exposes dict-valued var.json secrets in Rendered Templates
Apache Airflow exposes dict-valued var.json secrets in Rendered Templates
apache-airflow: before 3.3.1
Apache Airflow missing team context permits cross-team Dag actions and XCom reads
Apache Airflow missing team context permits cross-team Dag actions and XCom reads
apache-airflow: before 3.3.1
Apache Airflow XCom API permits unsafe deserialization through JSON string literals
Apache Airflow XCom API permits unsafe deserialization through JSON string literals
apache-airflow: before 3.3.1
Malicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in telebot-pro (PyPI)
Malicious code in morpho-sdk (PyPI)
Malicious code in morpho-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in euler-sdk (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in joule-sbx-poc (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI)
Malicious code in btcflip (PyPI)
Malicious code in btcflip (PyPI)
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
keras: before 3.15.0
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-sqlite: before 3.1.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
langgraph-checkpoint-postgres: before 3.1.1
Malicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI)
Malicious code in kotoraka (PyPI)
Malicious code in kotoraka (PyPI)
Malicious code in neutrl-core (PyPI)
Malicious code in neutrl-core (PyPI)
Malicious code in btcflx (PyPI)
Malicious code in btcflx (PyPI)
Apache Airflow Yandex Lockbox backend allows cross-team secret disclosure
Apache Airflow Yandex Lockbox backend allows cross-team secret disclosure
apache-airflow-providers-yandex: before 4.5.1
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
accelerate: all versions
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe
apache-airflow-providers-yandex: before 4.5.1
Tooling for PyPI
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.