PyPI incidents

Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNPyPI

Malicious code in crypto-trading-toolkit (PyPI)

Malicious code in crypto-trading-toolkit (PyPI)

21 hours ago
UNKNOWNPyPI

Malicious code in bitcoinlib-py (PyPI)

Malicious code in bitcoinlib-py (PyPI)

21 hours ago
UNKNOWNPyPI

Malicious code in bip39-py (PyPI)

Malicious code in bip39-py (PyPI)

21 hours ago
UNKNOWNPyPI

Malicious code in crypto-wallet-sdk (PyPI)

Malicious code in crypto-wallet-sdk (PyPI)

21 hours ago
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

1 day agoEPSS 0%
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

1 day agoEPSS 0%
UNKNOWNPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: before 49.0.0

1 day agoEPSS 0%
UNKNOWNPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

open-webui: 0.8.8 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

1 day agoEPSS 0%
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

1 day agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

1 day ago
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

1 day agoEPSS 0%
UNKNOWNPyPI

Malicious code in psbt-helpers (PyPI)

Malicious code in psbt-helpers (PyPI)

1 day ago
HIGHPyPI

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

open-webui: 0.9.0 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

open-webui: 0.9.0 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

open-webui: 0.8.0 → 0.11.0

1 day ago
MEDIUMPyPI

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

open-webui: 0.9.6 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

open-webui: 0.9.0 → 0.11.0

1 day ago
UNKNOWNPyPI

Malicious code in psbt-utils (PyPI)

Malicious code in psbt-utils (PyPI)

1 day ago
HIGHPyPI

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

open-webui: 0.9.6 → 0.11.0

1 day ago
MEDIUMPyPI

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

open-webui: 0.5.0 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

open-webui: 0.10.0 → 0.11.0

1 day ago
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

1 day agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

1 day agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

1 day agoEPSS 0%
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

1 day agoEPSS 0%
MEDIUMPyPI

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

mysql-mcp-server: before 0.3.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 day ago
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

1 day agoEPSS 0%
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

1 day agoEPSS 0%
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

1 day ago
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

1 day ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

1 day agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

1 day ago
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

1 day agoEPSS 0%
MEDIUMPyPI

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

nanobot-ai: before 0.2.1

1 day agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

1 day agoEPSS 0%
UNKNOWNPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: before 49.0.0

1 day agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 day ago
HIGHPyPI

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

open-webui: 0.8.8 → 0.11.0

1 day ago
UNKNOWNPyPI

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code in launchdarkly-ai-server-sdk (PyPI)

1 day ago
UNKNOWNPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI: DNS Rebinding SSRF Bypass

open-webui: before 0.11.0

1 day ago
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

open-webui: 0.10.0 → 0.11.0

1 day ago
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

open-webui: before 0.11.0

1 day ago
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

1 day agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

1 day agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent: all versions

1 day agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

1 day agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

1 day agoEPSS 0%
UNKNOWNPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

1 day agoEPSS 0%
UNKNOWNPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

1 day agoEPSS 0%
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

1 day agoEPSS 0%
HIGHPyPI

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

awxkit: all versions

1 day agoEPSS 0%
UNKNOWNPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

1 day agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

1 day agoEPSS 0%
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

open-webui: 0.7.0 → 0.11.0

1 day ago
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

open-webui: 0.6.34 → 0.11.0

1 day ago
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

1 day agoEPSS 0%
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

1 day agoEPSS 0%
UNKNOWNPyPI

Malicious code in coldcard-helpers (PyPI)

Malicious code in coldcard-helpers (PyPI)

1 day ago
UNKNOWNPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

1 day agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

1 day agoEPSS 0%
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

1 day agoEPSS 0%
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

1 day agoEPSS 0%
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

open-webui: 0.9.6 → 0.11.0

1 day ago
UNKNOWNPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

1 day agoEPSS 0%
MEDIUMPyPI

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

deepsearcher: all versions

1 day agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: before 0.15.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

open-webui: 0.9.6 → 0.11.0

1 day ago
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

1 day agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: all versions

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

1 day agoEPSS 0%
HIGHPyPI

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

1 day agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

1 day agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

1 day agoEPSS 0%
UNKNOWNPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

1 day agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

1 day ago
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

1 day agoEPSS 0%
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

1 day agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

1 day agoEPSS 0%
MODERATEPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

2 days agoEPSS 0%
HIGHPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: before 49.0.0

2 days agoEPSS 0%
HIGHPyPI

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

gitpython: before 3.1.57

2 days ago
HIGHPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

2 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in instalogin1234 (PyPI)

Malicious code in instalogin1234 (PyPI)

2 days ago
HIGHPyPI

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

gitpython: before 3.1.57

2 days ago
MEDIUMPyPI

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

gitpython: before 3.1.56

2 days ago
MODERATEPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

2 days agoEPSS 0%
MODERATEPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: before 49.0.0

2 days agoEPSS 0%
HIGHPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

2 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in wacve-utils (PyPI)

Malicious code in wacve-utils (PyPI)

3 days ago
UNKNOWNPyPI

Malicious code in trongriden (PyPI)

Malicious code in trongriden (PyPI)

3 days ago
UNKNOWNPyPI

Malicious code in nvtorch-oot-nightly (PyPI)

Malicious code in nvtorch-oot-nightly (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in trtllm-subdir-test (PyPI)

Malicious code in trtllm-subdir-test (PyPI)

4 days ago
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

5 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in telerape (PyPI)

Malicious code in telerape (PyPI)

5 days ago
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

5 days ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

5 days agoEPSS 0%
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

5 days agoEPSS 0%
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

5 days agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

5 days ago
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

5 days agoEPSS 0%
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

5 days agoEPSS 0%
HIGHPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

5 days agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

5 days ago
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

5 days agoEPSS 0%
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

5 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in aiprepkit (PyPI)

Malicious code in aiprepkit (PyPI)

5 days ago
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

5 days ago
UNKNOWNPyPI

Malicious code in asdk-plugin-legacy (PyPI)

Malicious code in asdk-plugin-legacy (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in asdk-plugin-alphagen (PyPI)

Malicious code in asdk-plugin-alphagen (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in catalogai (PyPI)

Malicious code in catalogai (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in aiassistcore (PyPI)

Malicious code in aiassistcore (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in cognikit (PyPI)

Malicious code in cognikit (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in ailaunchkit (PyPI)

Malicious code in ailaunchkit (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in aichannel (PyPI)

Malicious code in aichannel (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in reguestsc (PyPI)

Malicious code in reguestsc (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in walmart-genai-trace (PyPI)

Malicious code in walmart-genai-trace (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in asdk-plugin-ai-platform (PyPI)

Malicious code in asdk-plugin-ai-platform (PyPI)

5 days ago
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: before 2.26.7

6 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in ml-shared (PyPI)

Malicious code in ml-shared (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in ml-fdbk-shared (PyPI)

Malicious code in ml-fdbk-shared (PyPI)

6 days ago
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

6 days agoEPSS 0%
MODERATEPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

6 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in mcp-search-server (PyPI)

Malicious code in mcp-search-server (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in ml-nps-shared (PyPI)

Malicious code in ml-nps-shared (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in phabricator-client (PyPI)

Malicious code in phabricator-client (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in ml-data-shared (PyPI)

Malicious code in ml-data-shared (PyPI)

6 days ago
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

6 days agoEPSS 0%
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

6 days agoEPSS 0%
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

6 days agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

6 days agoEPSS 0%
UNKNOWNPyPI

Malicious code in ai-perf-toolkit (PyPI)

Malicious code in ai-perf-toolkit (PyPI)

6 days ago
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

1 week agoEPSS 0%
MODERATEPyPI

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

matrix-commander: all versions

1 week ago
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

1 week agoEPSS 0%
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

1 week agoEPSS 0%
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

1 week agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

1 week agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

1 week agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

1 week agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

1 week agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

1 week agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

1 week agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

1 week agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

1 week agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

1 week agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

1 week agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

1 week agoEPSS 0%
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

1 week agoEPSS 0%
UNKNOWNPyPI

Malicious code in cfgzen (PyPI)

Malicious code in cfgzen (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in blessclient (PyPI)

Malicious code in blessclient (PyPI)

1 week ago
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

1 week ago
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

1 week agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

1 week agoEPSS 0%
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

1 week agoEPSS 0%
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

1 week agoEPSS 0%
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

1 week agoEPSS 0%
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

1 week agoEPSS 0%
MODERATEPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

1 week agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

1 week agoEPSS 0%
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

1 week ago
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

1 week ago
UNKNOWNPyPI

Malicious code in discordnv (PyPI)

Malicious code in discordnv (PyPI)

1 week ago
CRITICALPyPI

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

gitpython: before 3.1.53

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

1 week agoEPSS 0%
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

1 week agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

1 week agoEPSS 0%
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

1 week agoEPSS 0%
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

1 week agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

1 week agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

1 week agoEPSS 0%
MODERATEPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

1 week agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

1 week agoEPSS 0%
MODERATEPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

1 week agoEPSS 0%
UNKNOWNPyPI

Malicious code in dev-helper-bg (PyPI)

Malicious code in dev-helper-bg (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in make-helper (PyPI)

Malicious code in make-helper (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in rasterkit (PyPI)

Malicious code in rasterkit (PyPI)

2 weeks ago
HIGHPyPI

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

gitpython: 3.1.50 → 3.1.51

2 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in animated-octo-spoon (PyPI)

Malicious code in animated-octo-spoon (PyPI)

2 weeks ago
HIGHPyPI

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

capstone: before 5.0.8

2 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in reimagined-broccoli (PyPI)

Malicious code in reimagined-broccoli (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in rasterkit-demo (PyPI)

Malicious code in rasterkit-demo (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in colorstack (PyPI)

Malicious code in colorstack (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in comp-colors (PyPI)

Malicious code in comp-colors (PyPI)

2 weeks ago
HIGHPyPI

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

gitpython: before 3.1.52

2 weeks agoEPSS 0%
HIGHPyPI

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1: before 0.6.4

2 weeks agoEPSS 0%
CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

gitpython: before 3.1.51

2 weeks agoEPSS 1%
CRITICALPyPI

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

gitpython: before 3.1.51

2 weeks agoEPSS 1%
UNKNOWNPyPI

Malicious code in fluffy-octo-broccoli (PyPI)

Malicious code in fluffy-octo-broccoli (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in vantrala (PyPI)

Malicious code in vantrala (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in nemopush (PyPI)

Malicious code in nemopush (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in ml-core-airflow-auth (PyPI)

Malicious code in ml-core-airflow-auth (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in automatic-octo-invention (PyPI)

Malicious code in automatic-octo-invention (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in kimichat (PyPI)

Malicious code in kimichat (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in kimitalk (PyPI)

Malicious code in kimitalk (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in roles-royce (PyPI)

Malicious code in roles-royce (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in trongrider (PyPI)

Malicious code in trongrider (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in shark-e2e-bnsneo (PyPI)

Malicious code in shark-e2e-bnsneo (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in neroteam-v1 (PyPI)

Malicious code in neroteam-v1 (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh3 (PyPI)

Malicious code in hello-world-test-mh3 (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh2 (PyPI)

Malicious code in hello-world-test-mh2 (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in data-parser-utils (PyPI)

Malicious code in data-parser-utils (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in tinkoff-cloud-apis-internal (PyPI)

Malicious code in tinkoff-cloud-apis-internal (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in python-devplatform-client (PyPI)

Malicious code in python-devplatform-client (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in dwh-kafka-client (PyPI)

Malicious code in dwh-kafka-client (PyPI)

2 weeks ago
HIGHPyPI

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

prompty: before 2.0.0b2

2 weeks agoEPSS 1%
UNKNOWNPyPI

Malicious code in abseil-py (PyPI)

Malicious code in abseil-py (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in northstart-sdk (PyPI)

Malicious code in northstart-sdk (PyPI)

3 weeks ago
HIGHPyPI

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

ddtrace: before 4.8.2

3 weeks agoEPSS 0%
HIGHPyPI

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

praisonaiagents: before 4.5.128

3 weeks agoEPSS 0%
HIGHPyPI

Pulp incorrectly assigns RBAC permissions in tasks that create objects

Pulp incorrectly assigns RBAC permissions in tasks that create objects

pulpcore: all versions

4 weeks agoEPSS 1%
MODERATEPyPI

aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

aiosmtplib: before 5.1.1

4 weeks ago
MODERATEPyPI

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

jupyterlab: before 4.5.9

1 month agoEPSS 0%
HIGHPyPI

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: before 0.42.1

1 month agoEPSS 0%
MEDIUMPyPI

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

pyjwt: 2.0.0 → 2.13.0

1 month agoEPSS 0%
MEDIUMPyPI

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

pyjwt: 2.0.0 → 2.13.0

1 month agoEPSS 0%
MEDIUMPyPI

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-sam

apache-airflow-providers-samba: before 4.12.6

1 month agoEPSS 1%
MEDIUMPyPI

Apache Airflow has a Path Traversal issue

Apache Airflow has a Path Traversal issue

apache-airflow-providers-samba: before 4.12.6

1 month agoEPSS 1%
HIGHPyPI

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

awxkit: all versions

1 month agoEPSS 0%
MEDIUMPyPI

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

mysql-mcp-server: before 0.3.0

1 month agoEPSS 0%
MEDIUMPyPI

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

deepsearcher: all versions

1 month agoEPSS 0%
HIGHPyPI

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

oslo-messaging: ≥ 1.0.0

2 months agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent: all versions

2 months agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: all versions

2 months agoEPSS 0%
MEDIUMPyPI

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

nanobot-ai: before 0.2.1

2 months agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: before 0.15.0

2 months agoEPSS 0%
CRITICALPyPI

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

gitpython: before 3.1.50

2 months agoEPSS 0%
HIGHPyPI

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

jupyter-server: before 2.18.0

3 months agoEPSS 1%
HIGHPyPI

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

jupyter-server: before 2.18.0

3 months agoEPSS 0%
CRITICALPyPI

MONAI: Unsafe functions lead to pickle deserialization rce

MONAI: Unsafe functions lead to pickle deserialization rce

monai: before 1.6.0

4 months ago
HIGHPyPI

Black: Arbitrary file writes from unsanitized user input in cache file name

Black: Arbitrary file writes from unsanitized user input in cache file name

black: 24.3.0 → 26.3.1

4 months agoEPSS 1%
CRITICALPyPI

num2words subjected to phishing attack, two versions published containing malware

num2words subjected to phishing attack, two versions published containing malware

num2words: ≥ 0.5.15

1 year ago
HIGHPyPI

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

dagster-ge: all versions

1 year agoEPSS 1%
CRITICALPyPI

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

airflow-diagrams: all versions

2 years agoEPSS 1%

Tooling for PyPI

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexMavenNuGetRubyGemscrates.ionpm