PyPI incidents

Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNPyPI

Malicious code in anthropic-sdk (PyPI)

Malicious code in anthropic-sdk (PyPI)

1 day ago
UNKNOWNPyPI

Malicious code in voxcpmtts3 (PyPI)

Malicious code in voxcpmtts3 (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in echogen (PyPI)

Malicious code in echogen (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmkit (PyPI)

Malicious code in voxcpmkit (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmintel (PyPI)

Malicious code in voxcpmintel (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in caoxiltts (PyPI)

Malicious code in caoxiltts (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmruntime (PyPI)

Malicious code in voxcpmruntime (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmui3 (PyPI)

Malicious code in voxcpmui3 (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmui4 (PyPI)

Malicious code in voxcpmui4 (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxcpmeval (PyPI)

Malicious code in voxcpmeval (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in voxel-tts (PyPI)

Malicious code in voxel-tts (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in infrabench (PyPI)

Malicious code in infrabench (PyPI)

2 days ago
CRITICALPyPI

Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)

Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)

headroom-ai: before 0.35.0

3 days ago
UNKNOWNPyPI

Malicious code in voxeval (PyPI)

Malicious code in voxeval (PyPI)

3 days ago
UNKNOWNPyPI

Malicious code in dedh-devops-automation (PyPI)

Malicious code in dedh-devops-automation (PyPI)

3 days ago
CRITICALPyPI

Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF

Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF

vibe-trading-ai: 0.1.0 → 0.1.7

3 days ago
CRITICALPyPI

Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths

Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths

dulwich: before 1.2.9

3 days ago
CRITICALPyPI

Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence

Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence

dulwich: 0.23.1 → 1.2.8

3 days ago
HIGHPyPI

Vibe-Trading file-read tools expose arbitrary server-readable files

Vibe-Trading file-read tools expose arbitrary server-readable files

vibe-trading-ai: 0.1.0 → 0.1.7

3 days ago
CRITICALPyPI

Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain

vibe-trading-ai: 0.1.0 → 0.1.7

3 days ago
CRITICALPyPI

Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections

Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections

dulwich: 0.24.0 → 1.2.8

3 days ago
HIGHPyPI

Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution

Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution

dulwich: before 1.2.9

3 days ago
MEDIUMPyPI

geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point

geopy: before 2.5.0

3 days ago
CRITICALPyPI

Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks

Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks

dulwich: 0.22.5 → 1.2.8

3 days ago
HIGHPyPI

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

lightrag-hku: before 1.5.5

4 days ago
HIGHPyPI

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

pyjwt: before 2.14.0

4 days ago
MEDIUMPyPI

JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs

JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs

jupyterlab: 4.6.0 → 4.6.4

4 days ago
HIGHPyPI

pypdf: Possible long runtimes when generating appearance streams

pypdf: Possible long runtimes when generating appearance streams

pypdf: before 6.19.0

4 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

open-webui: 0.10.0 → 0.11.1

4 days ago
HIGHPyPI

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vllm: before 0.28.0

4 days ago
MEDIUMPyPI

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

litellm: all versions

4 days ago
HIGHPyPI

foreman-mcp-server Inserts Sensitive Information into Log File

foreman-mcp-server Inserts Sensitive Information into Log File

foreman-mcp-server: all versions

4 days ago
HIGHPyPI

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

pyjwt: before 2.14.0

4 days ago
UNKNOWNPyPI

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.9.0

4 days ago
HIGHPyPI

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

open-webui: 0.9.0 → 0.11.1

4 days ago
HIGHPyPI

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path

djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path

djust: before 1.0.7

4 days ago
CRITICALPyPI

Hugging Face Transformers downloads custom generation code before trust consent

Hugging Face Transformers downloads custom generation code before trust consent

transformers: ≥ 4.49.0

4 days ago
UNKNOWNPyPI

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

jupyterlab: 4.6.0 → 4.6.4

4 days ago
HIGHPyPI

djust has broken object-level access control (IDOR)

djust has broken object-level access control (IDOR)

djust: before 1.0.7

4 days ago
MEDIUMPyPI

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

open-webui: 0.9.5 → 0.11.1

4 days ago
MEDIUMPyPI

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

oauthlib: 0.6.1 → 4.0.0

4 days ago
UNKNOWNPyPI

MCP Atlassian: SSRF Protection Bypass

MCP Atlassian: SSRF Protection Bypass

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

pypdf: Possible large memory usage when retrieving alphabetical page labels

pypdf: Possible large memory usage when retrieving alphabetical page labels

pypdf: before 6.19.0

4 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes with large amount of embedded files

pypdf: Possible long runtimes with large amount of embedded files

pypdf: before 6.19.0

4 days ago
MEDIUMPyPI

OpenStack Swift vulnerable to authenticated server-side request forgery

OpenStack Swift vulnerable to authenticated server-side request forgery

swift: before 2.37.2

4 days ago
MEDIUMPyPI

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

litellm: all versions

4 days ago
MEDIUMPyPI

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

nautobot: 3.0.0 → 3.1.8

4 days ago
HIGHPyPI

AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION

AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION

asyncssh: before 2.24.0

4 days ago
UNKNOWNPyPI

Home Assistant: XSS in Statistics Graph Card

Home Assistant: XSS in Statistics Graph Card

homeassistant: before 2026.7.0

4 days ago
CRITICALPyPI

Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

compliance-trestle: before 3.12.4

4 days ago
HIGHPyPI

pypdf: Possible long runtimes with large amount of embedded files

pypdf: Possible long runtimes with large amount of embedded files

pypdf: before 6.19.0

4 days ago
MEDIUMPyPI

wlc may disclose API tokens to project-configured URLs

wlc may disclose API tokens to project-configured URLs

wlc: before 2.0.1

4 days ago
HIGHPyPI

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

djust: before 1.0.7

4 days ago
UNKNOWNPyPI

urllib3: Chunked Deflate streaming can enter an infinite loop

urllib3: Chunked Deflate streaming can enter an infinite loop

urllib3: 2.6.2 → 2.8.0

4 days ago
HIGHPyPI

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

pyjwt: ≥ 2.11.0

4 days ago
HIGHPyPI

PyJWT accepts public JWK containers as HMAC secrets

PyJWT accepts public JWK containers as HMAC secrets

pyjwt: 2.13.0 → 2.14.0

4 days ago
MEDIUMPyPI

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

open-webui: 0.7.0 → 0.11.1

4 days ago
MEDIUMPyPI

sanic chunked trailer request smuggling allows hidden second request execution

sanic chunked trailer request smuggling allows hidden second request execution

sanic: before 24.12.1

4 days ago
MEDIUMPyPI

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

crossbar: before 26.7.1

4 days ago
HIGHPyPI

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

open-webui: before 0.11.1

4 days ago
HIGHPyPI

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

lightrag-hku: before 1.5.5

4 days ago
MEDIUMPyPI

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

lightrag-hku: before 1.5.5

4 days ago
HIGHPyPI

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

lightrag-hku: before 1.5.5

4 days ago
CRITICALPyPI

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

mysql-mcp-server: before 0.4.2

4 days ago
MEDIUMPyPI

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)

soupsieve: before 2.9.0

4 days ago
MEDIUMPyPI

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

pyjwt: before 2.14.0

4 days ago
UNKNOWNPyPI

Malicious code in friendly-tools (PyPI)

Malicious code in friendly-tools (PyPI)

4 days ago
UNKNOWNPyPI

mcp-atlassian has an incomplete SSRF remediation

mcp-atlassian has an incomplete SSRF remediation

mcp-atlassian: before 0.22.0

4 days ago
CRITICALPyPI

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

lmdeploy: 0.9.1 → 0.10.2

4 days ago
HIGHPyPI

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vllm: before 0.24.0

4 days ago
CRITICALPyPI

virtualenv bash and fish activation scripts execute commands embedded in paths

virtualenv bash and fish activation scripts execute commands embedded in paths

virtualenv: before 21.7.13

4 days ago
HIGHPyPI

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

hpack: Unbounded variable integer decoding can cause run-away computation on malformed input

hpack: Unbounded variable integer decoding can cause run-away computation on malformed input

hpack: before 4.2.0

4 days ago
UNKNOWNPyPI

Malicious code in spo365-graph (PyPI)

Malicious code in spo365-graph (PyPI)

4 days ago
UNKNOWNPyPI

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

djust: before 1.0.7

4 days ago
UNKNOWNPyPI

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

urllib3: 1.10.3 → 2.8.0

4 days ago
UNKNOWNPyPI

pypdf: Possible large memory usage when retrieving Roman page labels

pypdf: Possible large memory usage when retrieving Roman page labels

pypdf: before 6.17.0

4 days ago
CRITICALPyPI

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

plone-app-portlets: 5.0.0 → 5.0.8

4 days ago
HIGHPyPI

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

open-webui: 0.9.0 → 0.11.1

4 days ago
UNKNOWNPyPI

AnyIO process-pool workers can block indefinitely on undrained stderr

AnyIO process-pool workers can block indefinitely on undrained stderr

anyio: before 4.14.2

4 days ago
MEDIUMPyPI

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

litellm: all versions

4 days ago
HIGHPyPI

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

litellm: before 1.88.6

4 days ago
MEDIUMPyPI

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs

JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs

jupyterlab: 4.0.0 → 4.5.11

4 days ago
MEDIUMPyPI

social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

social-auth-core: before 5.0.0

4 days ago
HIGHPyPI

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

LiteLLM: M2M JWT Handler Has Improper Authorization

LiteLLM: M2M JWT Handler Has Improper Authorization

litellm: all versions

4 days ago
CRITICALPyPI

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

decepticon: before 1.1.17

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

notebook: 7.5.0 → 7.6.3

4 days ago
UNKNOWNPyPI

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

zapros: before 0.14.0

4 days ago
HIGHPyPI

PyJWT BOM Bypass

PyJWT BOM Bypass

pyjwt: 2.13.0 → 2.14.0

4 days ago
HIGHPyPI

pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

pypdf: before 6.18.1

4 days ago
HIGHPyPI

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

opencve: before 3.0.0

4 days ago
HIGHPyPI

social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend

social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend

social-auth-core: before 5.0.0

4 days ago
HIGHPyPI

djust has an authorization bypass on the WebSocket/SSE mount path

djust has an authorization bypass on the WebSocket/SSE mount path

djust: before 1.0.7

4 days ago
MEDIUMPyPI

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

lightrag-hku: before 1.5.5

4 days ago
UNKNOWNPyPI

pypdf: Possible large memory usage when parsing font data

pypdf: Possible large memory usage when parsing font data

pypdf: before 6.18.1

4 days ago
HIGHPyPI

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

open-webui: 0.9.0 → 0.11.1

4 days ago
HIGHPyPI

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

mcp-atlassian: before 0.22.0

4 days ago
CRITICALPyPI

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

decepticon-sdk: before 1.1.17

4 days ago
MEDIUMPyPI

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

nautobot: before 2.4.37

4 days ago
HIGHPyPI

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.11.1

4 days ago
CRITICALPyPI

ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade

ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade

esphome-device-builder: before 1.0.12

4 days ago
HIGHPyPI

pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

pypdf: before 6.18.1

4 days ago
HIGHPyPI

pypdf: Possible large memory usage when parsing font data

pypdf: Possible large memory usage when parsing font data

pypdf: before 6.18.1

4 days ago
HIGHPyPI

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

open-webui: 0.10.0 → 0.11.1

4 days ago
MEDIUMPyPI

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

litellm: all versions

4 days ago
HIGHPyPI

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

open-webui: 0.6.27 → 0.11.1

4 days ago
HIGHPyPI

plone.app.dexterity has a Denial of Service due to excessive title or description length

plone.app.dexterity has a Denial of Service due to excessive title or description length

plone-app-dexterity: before 3.2.3

4 days ago
HIGHPyPI

virtualenv: Command injection via --prompt in activate.bat (batch activator)

virtualenv: Command injection via --prompt in activate.bat (batch activator)

virtualenv: before 21.7.12

4 days ago
HIGHPyPI

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

mcp-atlassian: before 0.22.0

4 days ago
MEDIUMPyPI

social-auth-core has a Session Fixation issue

social-auth-core has a Session Fixation issue

social-auth-core: before 5.0.0

4 days ago
HIGHPyPI

pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf: before 6.18.0

4 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes when generating appearance streams

pypdf: Possible long runtimes when generating appearance streams

pypdf: before 6.19.0

4 days ago
HIGHPyPI

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

mnemosyne-memory: before 3.10.1

4 days ago
UNKNOWNPyPI

pypdf: Possible large memory usage when retrieving alphabetical page labels

pypdf: Possible large memory usage when retrieving alphabetical page labels

pypdf: before 6.19.0

4 days ago
UNKNOWNPyPI

pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)

pypdf: before 6.18.1

4 days ago
HIGHPyPI

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

mcp-atlassian: before 0.22.0

4 days ago
CRITICALPyPI

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

lmdeploy: 0.12.1 → 0.12.3

4 days ago
MEDIUMPyPI

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

picklescan: before 0.0.28

4 days ago
HIGHPyPI

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

doris-mcp-server: before 0.6.1

4 days ago
CRITICALPyPI

PickleScan has multiple stdlib modules with direct RCE not in blocklist

PickleScan has multiple stdlib modules with direct RCE not in blocklist

picklescan: before 1.0.4

4 days ago
HIGHPyPI

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

open-webui: 0.9.6 → 0.11.1

4 days ago
HIGHPyPI

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

accesscontrol: before 7.4

4 days ago
UNKNOWNPyPI

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups

anyio: 4.14.0 → 4.14.2

4 days ago
MEDIUMPyPI

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

pyjwt: 2.13.0 → 2.14.0

4 days ago
MEDIUMPyPI

LiteLLM: Admin Key Handler Has Improper Authorization

LiteLLM: Admin Key Handler Has Improper Authorization

litellm: all versions

4 days ago
HIGHPyPI

social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

social-auth-core: before 5.0.0

4 days ago
CRITICALPyPI

Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

compliance-trestle: before 3.12.4

4 days ago
CRITICALPyPI

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

decepticon-core: before 1.1.17

4 days ago
CRITICALPyPI

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

restrictedpython: before 8.4

4 days ago
MEDIUMPyPI

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

pyjwt: before 2.14.0

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

jupyterlite-core: before 0.8.4

4 days ago
HIGHPyPI

PyJWT: PyJWKClient follows redirects when fetching JWKS

PyJWT: PyJWKClient follows redirects when fetching JWKS

pyjwt: before 2.14.0

4 days ago
HIGHPyPI

social-auth-core has an Improper Authentication issue

social-auth-core has an Improper Authentication issue

social-auth-core: before 5.0.0

4 days ago
MEDIUMPyPI

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

litellm: all versions

4 days ago
UNKNOWNPyPI

Picklescan missing detection when calling built-in python library function timeit.timeit()

Picklescan missing detection when calling built-in python library function timeit.timeit()

picklescan: before 0.0.25

4 days ago
HIGHPyPI

MPXJ: XXE Vulnerability in MerlinReader

MPXJ: XXE Vulnerability in MerlinReader

mpxj: 5.5.5 → 16.4.1

4 days ago
UNKNOWNPyPI

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

urllib3: 1.26.0 → 2.8.0

4 days ago
MEDIUMPyPI

MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers

MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers

mpxj: 7.3.0 → 16.5.0

4 days ago
CRITICALPyPI

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

pyjwt: 2.9.0 → 2.14.0

4 days ago
CRITICALPyPI

sentence-transformers local model loading bypasses trust_remote_code and executes custom Python

sentence-transformers local model loading bypasses trust_remote_code and executes custom Python

sentence-transformers: before 5.6.0

4 days ago
CRITICALPyPI

Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing

Django GeoDjango spatial lookups allow file writes and outbound requests through GDAL raster parsing

django: before 5.2.17

4 days ago
HIGHPyPI

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

picklescan: before 0.0.29

4 days ago
UNKNOWNPyPI

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

litellm: before 1.83.9

4 days ago
CRITICALPyPI

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

jupyter-server: before 2.21.0

4 days ago
MEDIUMPyPI

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns

soupsieve: before 2.9.0

4 days ago
HIGHPyPI

pypdf: Possible large memory usage when retrieving Roman page labels

pypdf: Possible large memory usage when retrieving Roman page labels

pypdf: before 6.17.0

4 days ago
HIGHPyPI

PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

pyjwt: 2.13.0 → 2.14.0

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

jupyterlab: 3.0.0 → 4.5.11

4 days ago
HIGHPyPI

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

djust: before 1.0.7

4 days ago
HIGHPyPI

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

oauthlib: 3.0.0 → 4.0.0

4 days ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

open-webui: 0.8.11 → 0.11.1

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

jupyterlite-core: 0.7.0 → 0.8.4

4 days ago
HIGHPyPI

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

picklescan: before 0.0.33

4 days ago
MEDIUMPyPI

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)

pyjwt: 2.0.0a1 → 2.15.0

4 days ago
MEDIUMPyPI

Home Assistant: mDNS Server-Side Request Forgery

Home Assistant: mDNS Server-Side Request Forgery

homeassistant: before 2026.2.3

4 days ago
HIGHPyPI

Chainlit contains a session hijacking vulnerability

Chainlit contains a session hijacking vulnerability

chainlit: before 2.10.1

4 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)

pypdf: before 6.18.1

4 days ago
CRITICALPyPI

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

lmdeploy: 0.9.2 → 0.16.0

4 days ago
MEDIUMPyPI

LiteLLM: SSO Debug Flow Has Improper Authentication

LiteLLM: SSO Debug Flow Has Improper Authentication

litellm: all versions

4 days ago
HIGHPyPI

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

djust: before 1.0.7

4 days ago
HIGHPyPI

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

psd-tools: before 1.17.4

4 days ago
MEDIUMPyPI

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

autobahn: before 26.7.1

4 days ago
HIGHPyPI

Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files

Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files

streamlink: before 8.6.0

4 days ago
HIGHPyPI

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

djust: before 1.0.7

4 days ago
UNKNOWNPyPI

djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

djust: before 1.0.7

4 days ago
CRITICALPyPI

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

open-webui: 0.6.41 → 0.11.1

4 days ago
HIGHPyPI

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

djust: before 1.0.7

4 days ago
HIGHPyPI

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

jupyterlab: 4.5.0 → 4.5.11

4 days ago
UNKNOWNPyPI

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)

Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)

zapros: before 0.14.0

4 days ago
MEDIUMPyPI

LiteLLM: MCP Proxy Has Improper Authentication

LiteLLM: MCP Proxy Has Improper Authentication

litellm: before 1.84.0

4 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf: Possible long runtimes/large memory usage when parsing indirect objects

pypdf: before 6.18.0

4 days ago
HIGHPyPI

PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard

PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard

pyjwt: 2.4.0 → 2.14.0

4 days ago
UNKNOWNPyPI

Malicious code in shortneer (PyPI)

Malicious code in shortneer (PyPI)

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)

jupyterlab: 4.6.0 → 4.6.4

4 days ago
UNKNOWNPyPI

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

mesop: before 1.3.4

4 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

open-webui: 0.10.0 → 0.11.1

4 days ago
HIGHPyPI

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

djust: before 1.0.7

4 days ago
HIGHPyPI

SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

scbe-aethermoore: 4.0.2 → 4.2.1

4 days ago
HIGHPyPI

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

djust: before 1.0.7

4 days ago
HIGHPyPI

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

mcp-atlassian: before 0.22.0

4 days ago
UNKNOWNPyPI

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

anyio: before 4.14.2

4 days ago
HIGHPyPI

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

mcp-atlassian: before 0.22.0

4 days ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

jupyterlite: 0.7.0 → 0.8.4

4 days ago
HIGHPyPI

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

picklescan: before 0.0.29

4 days ago
MODERATEPyPI

urllib3: Chunked Deflate streaming can enter an infinite loop

urllib3: Chunked Deflate streaming can enter an infinite loop

urllib3: 2.6.2 → 2.8.0

5 days ago
MODERATEPyPI

GitPython submodule update path traversal can write outside the repository

GitPython submodule update path traversal can write outside the repository

gitpython: before 3.1.62

5 days ago
HIGHPyPI

Tornado: StaticFileHandler follows symlinks outside static root (path traversal)

Tornado: StaticFileHandler follows symlinks outside static root (path traversal)

tornado: before 6.5.9

5 days ago
MEDIUMPyPI

Tornado: Unbounded query-string argument count allows event-loop-stalling DoS

Tornado: Unbounded query-string argument count allows event-loop-stalling DoS

tornado: before 6.5.9

5 days ago
HIGHPyPI

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

urllib3: 1.10.3 → 2.8.0

5 days ago
CRITICALPyPI

GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution

GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution

gitpython: before 3.1.60

5 days ago
HIGHPyPI

tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM

tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM

tornado: before 6.5.9

5 days ago
HIGHPyPI

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

urllib3: HTTPS proxy TLS configuration may be ignored or overridden

urllib3: 1.26.0 → 2.8.0

5 days ago
HIGHPyPI

GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing

GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing

gitpython: before 3.1.60

5 days ago
HIGHPyPI

GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle

GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle

gitpython: 3.1.59 → 3.1.60

5 days ago
MODERATEPyPI

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

virtualenv: before 21.7.11

5 days ago
UNKNOWNPyPI

Malicious code in cleanup-string (PyPI)

Malicious code in cleanup-string (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in bfox-build-utils (PyPI)

Malicious code in bfox-build-utils (PyPI)

5 days ago
UNKNOWNPyPI

Malicious code in beautifytext (PyPI)

Malicious code in beautifytext (PyPI)

5 days ago
HIGHPyPI

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

pyjwt: before 2.14.0

5 days ago
MEDIUMPyPI

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)

pyjwt: 2.0.0a1 → 2.15.0

5 days ago
HIGHPyPI

virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

virtualenv: before 21.7.12

5 days ago
UNKNOWNPyPI

Malicious code in friendly-greeting-tools (PyPI)

Malicious code in friendly-greeting-tools (PyPI)

5 days ago
HIGHPyPI

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters

litellm: before 1.88.6

5 days ago
HIGHPyPI

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

pyjwt: ≥ 2.11.0

5 days ago
MEDIUMPyPI

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

pyjwt: before 2.14.0

6 days ago
HIGHPyPI

PyJWT accepts public JWK containers as HMAC secrets

PyJWT accepts public JWK containers as HMAC secrets

pyjwt: 2.13.0 → 2.14.0

6 days ago
MEDIUMPyPI

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

oauthlib: 0.6.1 → 4.0.0

6 days ago
MEDIUMPyPI

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

pyjwt: 2.13.0 → 2.14.0

6 days ago
HIGHPyPI

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

pyjwt: before 2.14.0

6 days ago
HIGHPyPI

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

oauthlib: 3.0.0 → 4.0.0

6 days ago
MEDIUMPyPI

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

pyjwt: before 2.14.0

6 days ago
HIGHPyPI

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

pyjwt: 2.9.0 → 2.14.0

6 days ago
HIGHPyPI

PyJWT: PyJWKClient follows redirects when fetching JWKS

PyJWT: PyJWKClient follows redirects when fetching JWKS

pyjwt: before 2.14.0

6 days ago
HIGHPyPI

PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

pyjwt: 2.13.0 → 2.14.0

6 days ago
HIGHPyPI

PyJWT BOM Bypass

PyJWT BOM Bypass

pyjwt: 2.13.0 → 2.14.0

6 days ago
HIGHPyPI

PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard

PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard

pyjwt: 2.4.0 → 2.14.0

6 days ago
CRITICALPyPI

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_run

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on Linux, '&' on Windows) are interpreted. If a victim loads and processes a crafted configuration fil

monai: before 1.6.0

1 week ago
CRITICALPyPI

MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. Th

MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.

monai: before 1.6.1rc0

1 week ago
UNKNOWNPyPI

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weight

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC sc

monai: all versions

1 week ago
UNKNOWNPyPI

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsa

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.

monai: before 1.6.0

1 week ago
UNKNOWNPyPI

Malicious code in donutpromotion (PyPI)

Malicious code in donutpromotion (PyPI)

1 week ago
UNKNOWNPyPI

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses n

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

monai: before 1.6.0

1 week ago
CRITICALPyPI

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/

MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle on an attacker-supplied pickle file, an object defining __reduce__ is executed during deserialization, resulting in arbitrary code execution in the context of the application.

monai: before 1.5.2

1 week ago
UNKNOWNPyPI

Malicious code in metrio (PyPI)

Malicious code in metrio (PyPI)

1 week ago
UNKNOWNPyPI

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar

MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration containing arbitrary code that executes when a victim loads the bundle using monai.bundle.load() or monai.bundle.run().

monai: before 1.6.1rc0

1 week ago
HIGHPyPI

SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests

scbe-aethermoore: 4.0.2 → 4.2.1

1 week ago
UNKNOWNPyPI

Malicious code in my-private-pkg (PyPI)

Malicious code in my-private-pkg (PyPI)

1 week ago
MEDIUMPyPI

social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend

social-auth-core: before 5.0.0

1 week ago
HIGHPyPI

Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files

Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files

streamlink: before 8.6.0

1 week ago
UNKNOWNPyPI

Malicious code in prosocks (PyPI)

Malicious code in prosocks (PyPI)

1 week ago
HIGHPyPI

social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing

social-auth-core: before 5.0.0

1 week ago
CRITICALPyPI

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context

decepticon-core: before 1.1.17

1 week ago
CRITICALPyPI

Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

compliance-trestle: before 3.12.4

1 week ago
HIGHPyPI

social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend

social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend

social-auth-core: before 5.0.0

1 week ago
CRITICALPyPI

Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

compliance-trestle: before 3.12.4

1 week ago
HIGHPyPI

social-auth-core has an Improper Authentication issue

social-auth-core has an Improper Authentication issue

social-auth-core: before 5.0.0

1 week ago
MODERATEPyPI

hpack: Unbounded variable integer decoding can cause run-away computation on malformed input

hpack: Unbounded variable integer decoding can cause run-away computation on malformed input

hpack: before 4.2.0

1 week ago
MEDIUMPyPI

social-auth-core has a Session Fixation issue

social-auth-core has a Session Fixation issue

social-auth-core: before 5.0.0

1 week ago
HIGHPyPI

plone.app.dexterity has a Denial of Service due to excessive title or description length

plone.app.dexterity has a Denial of Service due to excessive title or description length

plone-app-dexterity: 5.0.0 → 5.0.1

1 week ago
MODERATEPyPI

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service

zapros: before 0.14.0

1 week ago
MODERATEPyPI

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint

mesop: before 1.3.4

1 week ago
HIGHPyPI

Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)

Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)

zapros: before 0.14.0

1 week ago
CRITICALPyPI

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection

plone-app-portlets: 7.0.0 → 7.0.2

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue

mcp-atlassian: before 0.22.0

1 week ago
MEDIUMPyPI

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

nautobot: before 2.4.37

1 week ago
MEDIUMPyPI

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

autobahn: before 26.7.1

1 week ago
HIGHPyPI

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

mcp-atlassian: before 0.22.0

1 week ago
CRITICALPyPI

Home Assistant: XSS in Statistics Graph Card

Home Assistant: XSS in Statistics Graph Card

homeassistant: before 2026.7.0

1 week ago
HIGHPyPI

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)

mcp-atlassian: before 0.22.0

1 week ago
MEDIUMPyPI

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

nautobot: 3.0.0 → 3.1.8

1 week ago
HIGHPyPI

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: SSRF Protection Bypass

MCP Atlassian: SSRF Protection Bypass

mcp-atlassian: before 0.22.0

1 week ago
MEDIUMPyPI

wlc may disclose API tokens to project-configured URLs

wlc may disclose API tokens to project-configured URLs

wlc: before 2.0.1

1 week ago
MEDIUMPyPI

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

lightrag-hku: before 1.5.5

1 week ago
MEDIUMPyPI

Home Assistant: mDNS Server-Side Request Forgery

Home Assistant: mDNS Server-Side Request Forgery

homeassistant: before 2026.2.3

1 week ago
HIGHPyPI

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

lightrag-hku: before 1.5.5

1 week ago
CRITICALPyPI

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

mcp-atlassian: before 0.22.0

1 week ago
MEDIUMPyPI

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

lightrag-hku: before 1.5.5

1 week ago
HIGHPyPI

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

mcp-atlassian: before 0.22.0

1 week ago
MEDIUMPyPI

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

lightrag-hku: before 1.5.5

1 week ago
HIGHPyPI

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry

psd-tools: before 1.17.4

1 week ago
HIGHPyPI

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard

lightrag-hku: before 1.5.5

1 week ago
MEDIUMPyPI

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

mcp-atlassian has an incomplete SSRF remediation

mcp-atlassian has an incomplete SSRF remediation

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths

mcp-atlassian: before 0.22.0

1 week ago
HIGHPyPI

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

opencve: before 3.0.0

1 week ago
UNKNOWNPyPI

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.

vllm: before 0.30.0

2 weeks ago
UNKNOWNPyPI

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing valid requests to be delayed by up to 480 seconds while health checks continue returning success.

vllm: before 0.30.0

2 weeks ago
UNKNOWNPyPI

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.

vllm: before 0.30.0

2 weeks ago
UNKNOWNPyPI

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that crashes EngineCore and stops all inference.

vllm: before 0.30.0

2 weeks ago
UNKNOWNPyPI

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of varying lengths, causing the decode worker to terminate and become unavailable until restarted.

vllm: before 0.30.0

2 weeks ago
UNKNOWNPyPI

Malicious code in urc (PyPI)

Malicious code in urc (PyPI)

2 weeks ago
HIGHPyPI

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass

mnemosyne-memory: before 3.10.1

2 weeks ago
CRITICALPyPI

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

anyio: before 4.14.2

2 weeks ago
HIGHPyPI

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups

AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups

anyio: 4.14.0 → 4.14.2

2 weeks ago
UNKNOWNPyPI

Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

Downloaded seed wheels (pip/setuptools) are not integrity-checked before use

virtualenv: before 21.7.12

2 weeks ago
MODERATEPyPI

AnyIO process-pool workers can block indefinitely on undrained stderr

AnyIO process-pool workers can block indefinitely on undrained stderr

anyio: before 4.14.2

2 weeks ago
HIGHPyPI

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

lmdeploy: 0.12.3 → 0.15.0

2 weeks ago
CRITICALPyPI

virtualenv bash and fish activation scripts execute commands embedded in paths

virtualenv bash and fish activation scripts execute commands embedded in paths

virtualenv: before 21.7.13

2 weeks ago
UNKNOWNPyPI

Malicious code in py-venv-doctor (PyPI)

Malicious code in py-venv-doctor (PyPI)

2 weeks ago
CRITICALPyPI

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py

lmdeploy: 0.9.2 → 0.16.0

2 weeks ago
UNKNOWNPyPI

Command injection via --prompt in activate.bat (batch activator)

Command injection via --prompt in activate.bat (batch activator)

virtualenv: before 21.7.12

2 weeks ago
CRITICALPyPI

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading

lmdeploy: 0.12.1 → 0.12.3

2 weeks ago
UNKNOWNPyPI

Malicious code in requests-triwes (PyPI)

Malicious code in requests-triwes (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in marketing-mcp (PyPI)

Malicious code in marketing-mcp (PyPI)

2 weeks ago
MEDIUMPyPI

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns

soupsieve: before 2.9.0

2 weeks ago
HIGHPyPI

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: A template binding inherits a context safety grant it never earned (XSS)

djust: before 1.1.2

2 weeks ago
UNKNOWNPyPI

Malicious code in pyjstat-smooth (PyPI)

Malicious code in pyjstat-smooth (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in index-forum (PyPI)

Malicious code in index-forum (PyPI)

2 weeks ago
HIGHPyPI

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

accesscontrol: before 7.4

2 weeks ago
CRITICALPyPI

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

Jupyter Server: 5xx request logging leaks token-bearing Referer header values

jupyter-server: before 2.21.0

2 weeks ago
MEDIUMPyPI

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)

soupsieve: before 2.9.0

2 weeks ago
HIGHPyPI

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

vllm: before 0.28.0

2 weeks ago
MEDIUMPyPI

sanic chunked trailer request smuggling allows hidden second request execution

sanic chunked trailer request smuggling allows hidden second request execution

sanic: before 24.12.1

2 weeks ago
MODERATEPyPI

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

LiteLLM Proxy has server-side request forgery via the `user_config` request parameter

litellm: before 1.83.9

2 weeks ago
UNKNOWNPyPI

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection

virtualenv: before 21.7.11

2 weeks ago
HIGHPyPI

AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION

AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION

asyncssh: before 2.24.0

2 weeks ago
UNKNOWNPyPI

Malicious code in requests-auroras (PyPI)

Malicious code in requests-auroras (PyPI)

2 weeks ago
CRITICALPyPI

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

restrictedpython: before 8.4

2 weeks ago
UNKNOWNPyPI

Malicious code in requests-asetwe (PyPI)

Malicious code in requests-asetwe (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in aiosendletter (PyPI)

Malicious code in aiosendletter (PyPI)

2 weeks ago
HIGHPyPI

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

djust: before 1.1.1

2 weeks ago
UNKNOWNPyPI

Malicious code in licloud (PyPI)

Malicious code in licloud (PyPI)

2 weeks ago
HIGHPyPI

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

djust: before 1.0.7

2 weeks ago
UNKNOWNPyPI

Malicious code in trongappy (PyPI)

Malicious code in trongappy (PyPI)

2 weeks ago
HIGHPyPI

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

djust: before 1.0.7

2 weeks ago
CRITICALPyPI

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy

lmdeploy: 0.9.1 → 0.10.2

2 weeks ago
UNKNOWNPyPI

Malicious code in cli-anything-ai-market (PyPI)

Malicious code in cli-anything-ai-market (PyPI)

2 weeks ago
MODERATEPyPI

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

djust: before 1.0.7

2 weeks ago
UNKNOWNPyPI

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

Malicious code in rak-lab-yoav-orca-zrktd2cp5hjmo4x7 (PyPI)

2 weeks ago
HIGHPyPI

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

vllm: before 0.24.0

2 weeks ago
UNKNOWNPyPI

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

Malicious code in praetorian-mind-rce-test-2026 (PyPI)

2 weeks ago
CRITICALPyPI

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectio

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer — `dag_run_events_enabled` or `task_instance_events_enabled`, both disabled by default — build that client inside the scheduler process, so a user whose only privilege is editing Ai

apache-airflow-providers-apache-kafka: 1.15.0 → 2.0.0

2 weeks ago
HIGHPyPI

djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path

djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust has broken object-level access control (IDOR)

djust has broken object-level access control (IDOR)

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

djust: before 1.0.7

2 weeks ago
HIGHPyPI

djust has an authorization bypass on the WebSocket/SSE mount path

djust has an authorization bypass on the WebSocket/SSE mount path

djust: before 1.0.7

2 weeks ago
UNKNOWNPyPI

Malicious code in faiss-cpu-avx512 (PyPI)

Malicious code in faiss-cpu-avx512 (PyPI)

3 weeks ago
CRITICALPyPI

ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade

ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade

esphome-device-builder: before 1.0.12

3 weeks ago
UNKNOWNPyPI

Malicious code in chroma-client (PyPI)

Malicious code in chroma-client (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in python-fork (PyPI)

Malicious code in python-fork (PyPI)

3 weeks ago
UNKNOWNPyPI

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores t

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

vllm: before 0.28.0

3 weeks ago
CRITICALPyPI

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

mysql-mcp-server: before 0.4.2

3 weeks ago
UNKNOWNPyPI

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

3 weeks ago
HIGHPyPI

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

prowler-cloud: before 5.30.3

3 weeks ago
UNKNOWNPyPI

Malicious code in aitextkit-py (PyPI)

Malicious code in aitextkit-py (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in aitextutils-py (PyPI)

Malicious code in aitextutils-py (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in platform-telemetry-client (PyPI)

Malicious code in platform-telemetry-client (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in pymem-win (PyPI)

Malicious code in pymem-win (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in web3-eth-account (PyPI)

Malicious code in web3-eth-account (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in eth-account-web3 (PyPI)

Malicious code in eth-account-web3 (PyPI)

3 weeks ago
HIGHPyPI

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: before 0.117.2

3 weeks ago
HIGHPyPI

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents: before 1.6.58

3 weeks ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-websocket: before 1.1.1

3 weeks ago
HIGHPyPI

vLLM: Cross-User Data Leak Vulnerability

vLLM: Cross-User Data Leak Vulnerability

vllm: before 0.27.0

3 weeks ago
CRITICALPyPI

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

litellm: before 1.83.7

3 weeks ago
HIGHPyPI

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

apache-airflow: before 3.3.0

3 weeks ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql: before 1.1.1

3 weeks ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-checkpoint-mongodb: before 0.3.0

3 weeks ago
HIGHPyPI

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools: before 1.15.1

3 weeks ago
CRITICALPyPI

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

gitpython: before 3.1.58

3 weeks ago
HIGHPyPI

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

open-webui: 0.10.0 → 0.11.1

3 weeks ago
MEDIUMPyPI

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

open-webui: 0.9.0 → 0.11.1

3 weeks ago
HIGHPyPI

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh: before 2.23.1

3 weeks ago
HIGHPyPI

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

open-webui: 0.9.0 → 0.11.1

3 weeks ago
UNKNOWNPyPI

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

lightning: before 1.6.0

3 weeks ago
HIGHPyPI

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

eml-parser: before 3.0.2

3 weeks ago
UNKNOWNPyPI

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

copier: 9.5.0 → 9.15.2

3 weeks ago
CRITICALPyPI

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

chromadb: ≥ 0.5.0

3 weeks ago
UNKNOWNPyPI

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

chromadb: ≥ 0.4.17

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

open-webui: before 0.11.1

3 weeks ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.11.1

3 weeks ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

3 weeks ago
CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

gitpython: before 3.1.51

3 weeks ago
CRITICALPyPI

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

hydra-core: before 1.3.4

3 weeks ago
HIGHPyPI

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

open-webui: 0.9.0 → 0.11.1

3 weeks ago
CRITICALPyPI

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

compliance-trestle: before 3.12.4

3 weeks ago
HIGHPyPI

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents: before 1.6.58

3 weeks ago
MEDIUMPyPI

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

httpx2: before 2.11.0

3 weeks ago
UNKNOWNPyPI

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: before 6.15.0

3 weeks ago
MEDIUMPyPI

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

chainlit: 2.4.0rc0 → 2.12.0

3 weeks ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpx2: 2.6.0 → 2.10.0

3 weeks ago
HIGHPyPI

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml-parser: before 3.0.2

3 weeks ago
HIGHPyPI

asteval has a Sandbox Escape via BaseException Subclasses

asteval has a Sandbox Escape via BaseException Subclasses

asteval: before 1.0.9

3 weeks ago
MEDIUMPyPI

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

githacker: before 1.1.8

3 weeks ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

ironic: 17.0.0 → 29.0.6

3 weeks ago
CRITICALPyPI

Remote code execution in pytorch lightning

Remote code execution in pytorch lightning

pytorch-lightning: before 2.3.3

3 weeks ago
CRITICALPyPI

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

esphome-device-builder: before 1.0.10

3 weeks ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

icalendar: 7.1.0 → 7.1.3

3 weeks ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler: before 5.37.0

3 weeks ago
HIGHPyPI

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents: before 1.6.58

3 weeks ago
HIGHPyPI

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh: before 2.23.1

3 weeks ago
HIGHPyPI

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust: before 1.0.4

3 weeks ago
UNKNOWNPyPI

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

banks: before 2.4.5

3 weeks ago
CRITICALPyPI

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

document-merge-service: before 9.1.0

3 weeks ago
UNKNOWNPyPI

Malicious code in pylever (PyPI)

Malicious code in pylever (PyPI)

3 weeks ago
HIGHPyPI

PyTorch Lightning path traversal vulnerability

PyTorch Lightning path traversal vulnerability

lightning: before 2.4.0

3 weeks ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

3 weeks ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

3 weeks ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpcore2: before 2.10.0

3 weeks ago
HIGHPyPI

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

scrapy: before 2.17.0

3 weeks ago
HIGHPyPI

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

gitpython: before 3.1.52

3 weeks ago
HIGHPyPI

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

thrift: before 0.24.0

3 weeks ago
HIGHPyPI

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

gitpython: before 3.1.59

3 weeks ago
CRITICALPyPI

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

gitpython: before 3.1.51

3 weeks ago
HIGHPyPI

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

accelerate: all versions

3 weeks ago
HIGHPyPI

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

gitpython: before 3.1.58

3 weeks ago
HIGHPyPI

aiosmtplib: STARTTLS response injection

aiosmtplib: STARTTLS response injection

aiosmtplib: before 5.1.2

3 weeks ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

3 weeks ago
MEDIUMPyPI

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

open-webui: 0.9.5 → 0.11.1

3 weeks ago
HIGHPyPI

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

httpx2: before 2.12.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

open-webui: 0.7.0 → 0.11.1

3 weeks ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler-cloud: before 5.37.0

3 weeks ago
MEDIUMPyPI

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

httpx2: before 2.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.9.0

3 weeks ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonaiagents: 0.12.12 → 1.6.58

3 weeks ago
HIGHPyPI

Cognee allows non-superusers to overwrite global LLM configuration

Cognee allows non-superusers to overwrite global LLM configuration

cognee: before 1.5.0

3 weeks ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

3 weeks ago
MEDIUMPyPI

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

jupyterhub: before 5.5.0

3 weeks ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonai: 3.9.26 → 4.6.58

3 weeks ago
HIGHPyPI

PyTorch Lightning denial of service vulnerability

PyTorch Lightning denial of service vulnerability

lightning: all versions

3 weeks ago
MEDIUMPyPI

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

open-webui: 0.10.0 → 0.11.1

3 weeks ago
MEDIUMPyPI

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

kas: before 5.4

3 weeks ago
HIGHPyPI

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

praisonai: 4.6.34 → 4.6.58

3 weeks ago
CRITICALPyPI

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

chainlit: 2.4.0rc0 → 2.12.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

open-webui: 0.10.0 → 0.11.1

3 weeks ago
HIGHPyPI

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

plone-app-event: before 5.2.4

3 weeks ago
HIGHPyPI

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

thrift: before 0.24.0

3 weeks ago
HIGHPyPI

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: before 0.10.0

3 weeks ago
CRITICALPyPI

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

lightning: all versions

3 weeks ago
HIGHPyPI

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

mistune: 3.3.0 → 3.3.3

3 weeks ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-store-mongodb: before 0.4.0

3 weeks ago
HIGHPyPI

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

open-webui: 0.9.6 → 0.11.1

3 weeks ago
HIGHPyPI

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

open-webui: 0.6.27 → 0.11.1

3 weeks ago
HIGHPyPI

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

gitpython: before 3.1.58

3 weeks ago
HIGHPyPI

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

thrift: before 0.24.0

3 weeks ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

3 weeks ago
CRITICALPyPI

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

omnigent: before 0.3.0

3 weeks ago
HIGHPyPI

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

keras: before 3.15.0

3 weeks ago
MEDIUMPyPI

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml-parser: before 3.0.2

3 weeks ago
HIGHPyPI

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

praisonai: before 4.6.58

3 weeks ago
CRITICALPyPI

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

chromadb: ≥ 0.4.17

3 weeks ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

open-webui: 0.8.11 → 0.11.1

3 weeks ago
HIGHPyPI

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

praisonai: before 4.6.58

3 weeks ago
CRITICALPyPI

Compromise of PyTorch Lightning PyPi Package Versions

Compromise of PyTorch Lightning PyPi Package Versions

lightning: 2.6.2 → 2.6.4

3 weeks ago
CRITICALPyPI

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

nltk: before 3.10.3

3 weeks ago
CRITICALPyPI

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

gitpython: before 3.1.58

3 weeks ago
CRITICALPyPI

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

open-webui: 0.6.41 → 0.11.1

3 weeks ago
HIGHPyPI

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

praisonai: before 4.6.58

3 weeks ago
MEDIUMPyPI

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

open-webui: 0.9.5 → 0.11.1

3 weeks ago
UNKNOWNPyPI

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

justhtml: before 1.10.0

3 weeks ago
CRITICALPyPI

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

nltk: 3.10.0 → 3.10.3

3 weeks ago
HIGHPyPI

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

open-webui: 0.5.0 → 0.11.1

3 weeks ago
UNKNOWNPyPI

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: before 1.6.58

3 weeks ago
UNKNOWNPyPI

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents: 1.5.128 → 1.6.58

3 weeks ago
HIGHPyPI

OpenHarness remote resume commands expose other users' saved session snapshots

OpenHarness remote resume commands expose other users' saved session snapshots

openharness-ai: all versions

3 weeks ago
HIGHPyPI

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

nltk: before 3.10.1

3 weeks ago
HIGHPyPI

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

praisonai: before 4.6.58

3 weeks ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: before 6.16.1

3 weeks ago
UNKNOWNPyPI

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

nltk: before 3.10.3

3 weeks ago
MEDIUMPyPI

OpenHarness remote project-context commands allow persistent prompt poisoning

OpenHarness remote project-context commands allow persistent prompt poisoning

openharness-ai: all versions

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

open-webui: 0.10.0 → 0.11.1

3 weeks ago
HIGHPyPI

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

omnigent: before 0.3.0

3 weeks ago
UNKNOWNPyPI

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

lightning: before 1.6.0

3 weeks ago
HIGHPyPI

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

httpx2: 2.5.0 → 2.10.0

3 weeks ago
MEDIUMPyPI

Material for MkDocs: DOM XSS in search suggestions via query parameter

Material for MkDocs: DOM XSS in search suggestions via query parameter

mkdocs-material: 7.2.0 → 9.7.7

3 weeks ago
HIGHPyPI

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: before 0.10.0

3 weeks ago
HIGHPyPI

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning: before 2.3.3

3 weeks ago
CRITICALPyPI

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway: before 1.0.2

3 weeks ago
HIGHPyPI

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

MLflow AI Gateway permits SSRF through an unvalidated api_base

MLflow AI Gateway permits SSRF through an unvalidated api_base

mlflow: ≥ 3.13.0

3 weeks ago
MEDIUMPyPI

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

nltk: before 3.10.3

3 weeks ago
CRITICALPyPI

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

omnigent: before 0.3.0

3 weeks ago
HIGHPyPI

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

ONNX: TOCTOU arbitrary file read/write in save_external_dat

ONNX: TOCTOU arbitrary file read/write in save_external_dat

onnx: before 1.21.0

3 weeks ago
CRITICALPyPI

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

omnigent: before 0.3.0

3 weeks ago
MEDIUMPyPI

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

praisonai: before 4.6.58

3 weeks ago
CRITICALPyPI

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin: before 1.14.0

3 weeks ago
HIGHPyPI

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: before 1.6.58

3 weeks ago
CRITICALPyPI

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite-core: ≥ 2.0.0

3 weeks ago
MEDIUMPyPI

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

sqladmin: before 0.27.1

3 weeks ago
CRITICALPyPI

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed: before 5.1.2

3 weeks ago
HIGHPyPI

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents: before 1.6.58

3 weeks ago
HIGHPyPI

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

snowflake-sqlalchemy: 1.1.6 → 1.11.0

3 weeks ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: before 6.16.1

3 weeks ago
UNKNOWNPyPI

Malicious code in lucy-python-script-2030 (PyPI)

Malicious code in lucy-python-script-2030 (PyPI)

3 weeks ago
UNKNOWNPyPI

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

protego: before 0.6.2

3 weeks ago
MEDIUMPyPI

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy-mini: before 1.8.2

3 weeks ago
MEDIUMPyPI

PyOD persistence.load deserializes untrusted artifacts before validation

PyOD persistence.load deserializes untrusted artifacts before validation

pyod: 3.5.0 → 3.6.2

3 weeks ago
HIGHPyPI

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone-app-portlets: before 5.0.8

3 weeks ago
UNKNOWNPyPI

Snowflake Connector for Python improperly verifies TLS hostnames

Snowflake Connector for Python improperly verifies TLS hostnames

snowflake-connector-python: before 3.18.1

3 weeks ago
CRITICALPyPI

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

xinference: before 2.7.0

3 weeks ago
CRITICALPyPI

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp: before 0.2.1

3 weeks ago
HIGHPyPI

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

transformers: before 5.10.0

3 weeks ago
UNKNOWNPyPI

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vllm: 0.21.0 → 0.26.0

3 weeks ago
MEDIUMPyPI

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vllm: before 0.26.0

3 weeks ago
UNKNOWNPyPI

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: before 6.16.0

3 weeks ago
HIGHPyPI

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint: before 70.0

3 weeks ago
HIGHPyPI

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

restrictedpython: before 8.3

3 weeks ago
HIGHPyPI

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vllm: before 0.26.0

3 weeks ago
UNKNOWNPyPI

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: before 0.6.0

3 weeks ago
MEDIUMPyPI

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

webob: before 1.8.11

3 weeks ago
MEDIUMPyPI

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

starlette-admin: before 0.16.1

3 weeks ago
MEDIUMPyPI

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vllm: before 0.26.0

3 weeks ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

3 weeks ago
MEDIUMPyPI

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vllm: before 0.26.0

3 weeks ago
HIGHPyPI

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

weblate: before 2026.7

3 weeks ago
UNKNOWNPyPI

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

wsgidav: before 4.3.5

3 weeks ago
UNKNOWNPyPI

Windows ML CLI: CORS misconfig enables localhost RCE

Windows ML CLI: CORS misconfig enables localhost RCE

winml-cli: before 0.4.0

3 weeks ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

wagtail: before 7.0.9

3 weeks ago
MEDIUMPyPI

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

weblate: before 2026.7

3 weeks ago
HIGHPyPI

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

tornado: before 6.5.8

3 weeks ago
HIGHPyPI

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: 0.4.7 → 0.24.0

3 weeks ago
MEDIUMPyPI

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

githacker: before 1.1.8

3 weeks ago
UNKNOWNPyPI

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Malicious code in bq-build-probe-vrp-2026 (PyPI)

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

open-webui: 0.10.0 → 0.11.1

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

open-webui: 0.5.0 → 0.11.1

3 weeks ago
UNKNOWNPyPI

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrar

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.

gitpython: before 3.1.60

3 weeks ago
CRITICALPyPI

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

esphome-device-builder: before 1.0.10

3 weeks ago
MEDIUMPyPI

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

sqladmin: before 0.27.1

3 weeks ago
HIGHPyPI

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that pro

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per commit access.

gitpython: before 3.1.60

3 weeks ago
UNKNOWNPyPI

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

gitpython: before 3.1.60

3 weeks ago
UNKNOWNPyPI

Malicious code in websetup (PyPI)

Malicious code in websetup (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Malicious code in databricks-webapp-navigation-homepage (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in bq-sdist-probe-vrp (PyPI)

Malicious code in bq-sdist-probe-vrp (PyPI)

3 weeks ago
HIGHPyPI

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint: before 70.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

open-webui: 0.9.5 → 0.11.1

3 weeks ago
HIGHPyPI

Windows ML CLI: CORS misconfig enables localhost RCE

Windows ML CLI: CORS misconfig enables localhost RCE

winml-cli: before 0.4.0

3 weeks ago
MEDIUMPyPI

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

httpx2: before 2.11.0

3 weeks ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpcore2: before 2.10.0

3 weeks ago
HIGHPyPI

NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

nltk: before 3.9.3

3 weeks ago
HIGHPyPI

NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

nltk: before 3.9.4

3 weeks ago
HIGHPyPI

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

nltk: before 3.10.3

3 weeks ago
CRITICALPyPI

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

nltk: 3.10.0 → 3.10.2

3 weeks ago
HIGHPyPI

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

NLTK: Corpus Reader Sandbox Bypass

NLTK: Corpus Reader Sandbox Bypass

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

nltk: before 3.10.0

3 weeks ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler: before 5.37.0

3 weeks ago
CRITICALPyPI

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

nltk: before 3.10.3

3 weeks ago
CRITICALPyPI

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

gitpython: before 3.1.59

3 weeks ago
HIGHPyPI

NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

gitpython: before 3.1.59

3 weeks ago
HIGHPyPI

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

nltk: 3.10.0 → 3.10.2

3 weeks ago
HIGHPyPI

NLTK: Stable FrameNet and NKJP readers parse outside-root XML

NLTK: Stable FrameNet and NKJP readers parse outside-root XML

nltk: before 3.10.0

3 weeks ago
MODERATEPyPI

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

nltk: before 3.10.3

3 weeks ago
MEDIUMPyPI

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

httpx2: before 2.11.0

3 weeks ago
HIGHPyPI

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

httpx2: 2.5.0 → 2.10.0

3 weeks ago
HIGHPyPI

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

gitpython: before 3.1.59

3 weeks ago
HIGHPyPI

vLLM: Cross-User Data Leak Vulnerability

vLLM: Cross-User Data Leak Vulnerability

vllm: before 0.27.0

3 weeks ago
CRITICALPyPI

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

gitpython: before 3.1.59

3 weeks ago
HIGHPyPI

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vllm: before 0.26.0

3 weeks ago
HIGHPyPI

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

gitpython: before 3.1.59

3 weeks ago
HIGHPyPI

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

httpx2: before 2.12.0

3 weeks ago
UNKNOWNPyPI

Malicious code in cv-train (PyPI)

Malicious code in cv-train (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in telegram-helper (PyPI)

Malicious code in telegram-helper (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in minecraftmodes (PyPI)

Malicious code in minecraftmodes (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in dac-tools (PyPI)

Malicious code in dac-tools (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in trongridew (PyPI)

Malicious code in trongridew (PyPI)

4 weeks ago
HIGHPyPI

Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit

Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit

local-operator: before 0.47.5

4 weeks ago
HIGHPyPI

Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator

Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator

local-operator: before 0.47.5

4 weeks ago
UNKNOWNPyPI

Malicious code in dbt-sa-cli (PyPI)

Malicious code in dbt-sa-cli (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in proxycer (PyPI)

Malicious code in proxycer (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in astlsi (PyPI)

Malicious code in astlsi (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in tpu-raiden-jax (PyPI)

Malicious code in tpu-raiden-jax (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in olympuslib (PyPI)

Malicious code in olympuslib (PyPI)

4 weeks ago
MEDIUMPyPI

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vllm: before 0.26.0

4 weeks ago
UNKNOWNPyPI

Malicious code in chartkit-core (PyPI)

Malicious code in chartkit-core (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in qoeoe (PyPI)

Malicious code in qoeoe (PyPI)

4 weeks ago
MEDIUMPyPI

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vllm: before 0.26.0

4 weeks ago
UNKNOWNPyPI

Malicious code in timeweave (PyPI)

Malicious code in timeweave (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in houdus (PyPI)

Malicious code in houdus (PyPI)

4 weeks ago
MODERATEPyPI

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vllm: 0.21.0 → 0.26.0

4 weeks ago
UNKNOWNPyPI

Malicious code in pymaas (PyPI)

Malicious code in pymaas (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in tsshare (PyPI)

Malicious code in tsshare (PyPI)

tsshare: all versions

4 weeks ago
MEDIUMPyPI

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vllm: before 0.26.0

4 weeks ago
UNKNOWNPyPI

Malicious code in metricboxlite (PyPI)

Malicious code in metricboxlite (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in env-validator-tool (PyPI)

Malicious code in env-validator-tool (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in 0requests (PyPI)

Malicious code in 0requests (PyPI)

4 weeks ago
HIGHPyPI

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: 0.4.7 → 0.24.0

4 weeks ago
UNKNOWNPyPI

Malicious code in py-2equests (PyPI)

Malicious code in py-2equests (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in py-0requests (PyPI)

Malicious code in py-0requests (PyPI)

4 weeks ago
MEDIUMPyPI

Material for MkDocs: DOM XSS in search suggestions via query parameter

Material for MkDocs: DOM XSS in search suggestions via query parameter

mkdocs-material: 7.2.0 → 9.7.7

4 weeks ago
UNKNOWNPyPI

Malicious code in uvhttp-custom (PyPI)

Malicious code in uvhttp-custom (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in telemetry-helper (PyPI)

Malicious code in telemetry-helper (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in trongridi (PyPI)

Malicious code in trongridi (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in asti (PyPI)

Malicious code in asti (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in company-sdk (PyPI)

Malicious code in company-sdk (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in py-1requests (PyPI)

Malicious code in py-1requests (PyPI)

4 weeks ago
MODERATEPyPI

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

banks: before 2.4.5

4 weeks ago
MEDIUMPyPI

NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

nltk: before 3.10.3

4 weeks ago
MODERATEPyPI

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

nltk: before 3.10.0

4 weeks ago
HIGHPyPI

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

mistune: 3.3.0 → 3.3.3

4 weeks ago
CRITICALPyPI

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

omnigent: before 0.3.0

4 weeks ago
CRITICALPyPI

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

omnigent: before 0.3.0

4 weeks ago
HIGHPyPI

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

nltk: before 3.10.3

4 weeks ago
HIGHPyPI

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

nltk: all versions

4 weeks ago
HIGHPyPI

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

scrapy: before 2.17

4 weeks ago
MEDIUMPyPI

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web

pyspark: 3.0.0 → 3.5.8

4 weeks ago
CRITICALPyPI

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

omnigent: before 0.3.0

4 weeks ago
HIGHPyPI

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

tornado: before 6.5.8

4 weeks ago
MODERATEPyPI

NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'

NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'

nltk: before 3.10.3

4 weeks ago
MEDIUMPyPI

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

nltk: before 3.10.3

4 weeks ago
MODERATEPyPI

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: before 6.15.0

4 weeks ago
MODERATEPyPI

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

nltk: before 3.10.3

4 weeks ago
HIGHPyPI

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

nltk: before 3.10.0

4 weeks ago
HIGHPyPI

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

omnigent: before 0.3.0

4 weeks ago
MODERATEPyPI

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: before 0.6.0

4 weeks ago
UNKNOWNPyPI

Malicious code in tallyboxlite (PyPI)

Malicious code in tallyboxlite (PyPI)

4 weeks ago
CRITICALPyPI

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

mlflow: 2.1.0 → 3.15.0

4 weeks ago
UNKNOWNPyPI

Malicious code in gcphelpit (PyPI)

Malicious code in gcphelpit (PyPI)

4 weeks ago
MODERATEPyPI

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: before 6.16.0

4 weeks ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: before 6.16.1

4 weeks ago
UNKNOWNPyPI

Malicious code in syswatch (PyPI)

Malicious code in syswatch (PyPI)

4 weeks ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: before 6.16.1

4 weeks ago
CRITICALPyPI

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

nltk: before 3.10.3

4 weeks ago
CRITICALPyPI

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

nltk: before 3.10.3

4 weeks ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

4 weeks ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

4 weeks ago
MODERATEPyPI

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: before 6.5.8

4 weeks ago
LOWPyPI

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

tornado: 6.5.5 → 6.5.8

4 weeks ago
CRITICALPyPI

Hugging Face Transformers downloads custom generation code before trust consent

Hugging Face Transformers downloads custom generation code before trust consent

transformers: ≥ 4.49.0

4 weeks ago
UNKNOWNPyPI

Malicious code in pyservercheck (PyPI)

Malicious code in pyservercheck (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in trongridor (PyPI)

Malicious code in trongridor (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in tronlinker (PyPI)

Malicious code in tronlinker (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in auth-app-streamlit (PyPI)

Malicious code in auth-app-streamlit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in flask-header-guard (PyPI)

Malicious code in flask-header-guard (PyPI)

1 month ago
HIGHPyPI

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone-app-portlets: 7.0.0 → 7.0.2

1 month ago
CRITICALPyPI

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin: before 1.14.0

1 month ago
UNKNOWNPyPI

Malicious code in pygame-renderkit (PyPI)

Malicious code in pygame-renderkit (PyPI)

1 month ago
HIGHPyPI

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

restrictedpython: before 8.3

1 month ago
UNKNOWNPyPI

Malicious code in yamlformat-tools (PyPI)

Malicious code in yamlformat-tools (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in yaml-report-formatter (PyPI)

Malicious code in yaml-report-formatter (PyPI)

1 month ago
HIGHPyPI

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

wsgidav: before 4.3.5

1 month ago
UNKNOWNPyPI

Malicious code in yamlformatter-utils (PyPI)

Malicious code in yamlformatter-utils (PyPI)

1 month ago
CRITICALPyPI

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

compliance-trestle: before 3.12.4

1 month ago
MODERATEPyPI

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

aiir: before 1.7.0

1 month ago
UNKNOWNPyPI

Malicious code in calcboxlite (PyPI)

Malicious code in calcboxlite (PyPI)

1 month ago
HIGHPyPI

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

weblate: before 2026.7

1 month ago
HIGHPyPI

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

plone-app-event: before 5.2.4

1 month ago
HIGHPyPI

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

protego: before 0.6.2

1 month ago
MEDIUMPyPI

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

weblate: before 2026.7

1 month ago
UNKNOWNPyPI

Malicious code in sap-quarterly-report (PyPI)

Malicious code in sap-quarterly-report (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in flyteplugins-redis (PyPI)

Malicious code in flyteplugins-redis (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in decoris (PyPI)

Malicious code in decoris (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in mathkitlite (PyPI)

Malicious code in mathkitlite (PyPI)

1 month ago
HIGHPyPI

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

Malicious code in flyteplugins-agento11y (PyPI)

Malicious code in flyteplugins-agento11y (PyPI)

1 month ago
UNKNOWNPyPI

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causin

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

openssl-encrypt: before 1.4.9

1 month ago
MEDIUMPyPI

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext password is written to stderr. Anyone with access to that output (terminal scrollback, merged 2>&1 output,

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main password. Any local user can read the steganography password from /proc/<pid>/cmdline for the lifetime of the subprocess. Fixed in 1.4.9.

openssl-encrypt: before 1.4.9

1 month ago
HIGHPyPI

aiosmtplib: STARTTLS response injection

aiosmtplib: STARTTLS response injection

aiosmtplib: before 5.1.2

1 month ago
UNKNOWNPyPI

Malicious code in ekx-report-utils (PyPI)

Malicious code in ekx-report-utils (PyPI)

1 month ago
UNKNOWNPyPI

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a result the token is printed in cleartext to stderr under --debug (even without --unsafe-show-secrets), persisting the credential in logs and terminal history. Fixed in 1.4.9.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.

openssl-encrypt: before 1.4.9

1 month ago
CRITICALPyPI

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

litellm: before 1.83.7

1 month ago
UNKNOWNPyPI

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords.

openssl-encrypt: before 1.4.9

1 month ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.

nltk: before 3.10.3

1 month ago
MEDIUMPyPI

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

netron: before 9.1.3

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.

openssl-encrypt: before 1.4.9

1 month ago
MEDIUMPyPI

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

netron: before 9.1.3

1 month ago
MEDIUMPyPI

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

webob: before 1.8.11

1 month ago
UNKNOWNPyPI

Malicious code in flyteplugins-nsight (PyPI)

Malicious code in flyteplugins-nsight (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in flyteplugins-echo (PyPI)

Malicious code in flyteplugins-echo (PyPI)

1 month ago
CRITICALPyPI

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.

openssl-encrypt: before 1.4.9

1 month ago
MEDIUMPyPI

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

netron: before 9.1.3

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing i

nltk: before 3.10.3

1 month ago
CRITICALPyPI

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite-core: ≥ 2.0.0

1 month ago
HIGHPyPI

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh: before 2.23.1

1 month ago
UNKNOWNPyPI

Malicious code in bigquery-agent-analytics-tracing (PyPI)

Malicious code in bigquery-agent-analytics-tracing (PyPI)

1 month ago
MEDIUMPyPI

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

starlette-admin: before 0.16.1

1 month ago
HIGHPyPI

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

openwisp-ipam: before 1.2.1

1 month ago
UNKNOWNPyPI

Malicious code in syntaxerror-package-12345 (PyPI)

Malicious code in syntaxerror-package-12345 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in rce-test (PyPI)

Malicious code in rce-test (PyPI)

1 month ago
MEDIUMPyPI

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

kas: before 5.4

1 month ago
UNKNOWNPyPI

Malicious code in trongridet (PyPI)

Malicious code in trongridet (PyPI)

1 month ago
HIGHPyPI

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh: before 2.23.1

1 month ago
CRITICALPyPI

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

pantheon-agents: 0.6.1 → 0.6.4

1 month ago
UNKNOWNPyPI

Malicious code in 0xfighter3 (PyPI)

Malicious code in 0xfighter3 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

1 month ago
HIGHPyPI

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust: before 1.0.4

1 month ago
MEDIUMPyPI

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy-mini: before 1.8.2

1 month ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql: before 1.1.1

1 month ago
HIGHPyPI

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: before 0.117.2

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

nltk: before 3.10.3

1 month ago
HIGHPyPI

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

icalendar: 7.1.0 → 7.1.3

1 month ago
HIGHPyPI

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

praisonai: before 4.6.58

1 month ago
CRITICALPyPI

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed: before 5.1.2

1 month ago
UNKNOWNPyPI

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.

vllm: before 0.27.0

1 month ago
HIGHPyPI

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

praisonai: before 4.6.58

1 month ago
UNKNOWNPyPI

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code wit

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attack

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

nltk: before 3.10.3

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

nltk: before 3.10.3

1 month ago
HIGHPyPI

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

praisonai: before 4.6.58

1 month ago
HIGHPyPI

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.

uff: all versions

1 month ago
HIGHPyPI

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents: 1.5.128 → 1.6.58

1 month ago
HIGHPyPI

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents: before 1.6.58

1 month ago
HIGHPyPI

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents: before 1.6.58

1 month ago
HIGHPyPI

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

praisonai: 4.6.34 → 4.6.58

1 month ago
UNKNOWNPyPI

Malicious code in python-walletlibr-v (PyPI)

Malicious code in python-walletlibr-v (PyPI)

1 month ago
HIGHPyPI

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http: before 1.1.4

1 month ago
HIGHPyPI

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway: before 1.0.0

1 month ago
UNKNOWNPyPI

Malicious code in minecraft-ytreceiver (PyPI)

Malicious code in minecraft-ytreceiver (PyPI)

1 month ago
MEDIUMPyPI

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

jupyterhub: before 5.5.0

1 month ago
HIGHPyPI

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http: before 1.1.4

1 month ago
MEDIUMPyPI

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

praisonai: before 4.6.58

1 month ago
HIGHPyPI

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: before 1.6.58

1 month ago
MEDIUMPyPI

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml-parser: before 3.0.2

1 month ago
MEDIUMPyPI

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

chainlit: 2.4.0rc0 → 2.12.0

1 month ago
HIGHPyPI

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

praisonai: before 4.6.58

1 month ago
UNKNOWNPyPI

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.

nltk: before 3.10.3

1 month ago
HIGHPyPI

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

praisonai: before 4.6.58

1 month ago
HIGHPyPI

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents: before 1.6.58

1 month ago
HIGHPyPI

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: before 1.6.58

1 month ago
HIGHPyPI

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

praisonai: before 4.6.58

1 month ago
HIGHPyPI

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

praisonai: before 4.6.58

1 month ago
HIGHPyPI

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents: before 1.6.58

1 month ago
CRITICALPyPI

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

chainlit: 2.4.0rc0 → 2.12.0

1 month ago
HIGHPyPI

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

praisonai: before 4.6.58

1 month ago
CRITICALPyPI

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp: before 0.2.1

1 month ago
HIGHPyPI

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

praisonai: before 4.6.58

1 month ago
HIGHPyPI

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml-parser: before 3.0.2

1 month ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonaiagents: 0.12.12 → 1.6.58

1 month ago
HIGHPyPI

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

praisonai: before 4.6.58

1 month ago
HIGHPyPI

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

eml-parser: before 3.0.2

1 month ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

1 month ago
CRITICALPyPI

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway: before 1.0.2

1 month ago
UNKNOWNPyPI

Malicious code in multyproccess (PyPI)

Malicious code in multyproccess (PyPI)

1 month ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

1 month ago
UNKNOWNPyPI

Malicious code in msrcpoc (PyPI)

Malicious code in msrcpoc (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in py-devoli-common (PyPI)

Malicious code in py-devoli-common (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in envprovision (PyPI)

Malicious code in envprovision (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in cryptgraphy (PyPI)

Malicious code in cryptgraphy (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in mlflow-otel-instrumentor (PyPI)

Malicious code in mlflow-otel-instrumentor (PyPI)

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebin

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.

nltk: before 3.9.4

1 month ago
UNKNOWNPyPI

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

nltk: before 3.10.0

1 month ago
HIGHPyPI

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

nltk: before 3.9.3

1 month ago
HIGHPyPI

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.

nltk: before 3.9.4

1 month ago
UNKNOWNPyPI

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.

nltk: 3.10.0 → 3.10.2

1 month ago
MEDIUMPyPI

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who contro

nltk: 3.9.4 → 3.10.3

1 month ago
CRITICALPyPI

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

nltk: 3.10.0 → 3.10.3

1 month ago
MEDIUMPyPI

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

nltk: 3.9.4 → 3.10.3

1 month ago
UNKNOWNPyPI

Malicious code in scrambleeeer (PyPI)

Malicious code in scrambleeeer (PyPI)

1 month ago
CRITICALPyPI

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

hydra-core: before 1.3.4

1 month ago
UNKNOWNPyPI

Malicious code in scrambleeer (PyPI)

Malicious code in scrambleeer (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in requests-crypt (PyPI)

Malicious code in requests-crypt (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in boto4 (PyPI)

Malicious code in boto4 (PyPI)

1 month ago
CRITICALPyPI

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

xinference: before 2.7.0

1 month ago
UNKNOWNPyPI

Malicious code in reqcrypts (PyPI)

Malicious code in reqcrypts (PyPI)

1 month ago
HIGHPyPI

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

nltk: before 3.10.1

1 month ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

1 month ago
HIGHPyPI

asteval has a Sandbox Escape via BaseException Subclasses

asteval has a Sandbox Escape via BaseException Subclasses

asteval: before 1.0.9

1 month ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

1 month ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

wagtail: before 7.0.9

1 month ago
HIGHPyPI

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval: before 1.0.9

1 month ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

1 month ago
MEDIUMPyPI

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node: before 0.9.0a11

1 month ago
HIGHPyPI

Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

wagtail: 7.3 → 7.3.3

1 month ago
HIGHPyPI

Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

wagtail: before 7.0.8

1 month ago
MODERATEPyPI

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

zoo-kcl: before 0.3.153

1 month ago
HIGHPyPI

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

wagtail: before 7.0.9

1 month ago
MEDIUMPyPI

Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

wagtail: before 7.0.8

1 month ago
MEDIUMPyPI

Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

wagtail: before 7.0.8

1 month ago
MODERATEPyPI

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

zoo-kcl: before 0.3.129

1 month ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

wagtail: before 7.0.8

1 month ago
MEDIUMPyPI

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

wagtail: before 7.0.9

1 month ago
HIGHPyPI

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

wagtail: before 7.0.9

1 month ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

1 month ago
MEDIUMPyPI

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

wagtail: before 7.0.9

1 month ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

1 month ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-checkpoint-mongodb: before 0.3.0

1 month ago
HIGHPyPI

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

copier: 9.5.0 → 9.15.2

1 month ago
HIGHPyPI

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: before 0.10.0

1 month ago
HIGHPyPI

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: before 0.10.0

1 month ago
HIGHExploitedPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: before 3.15.0

1 month ago
UNKNOWNPyPI

Malicious code in reqcrypt-dev (PyPI)

Malicious code in reqcrypt-dev (PyPI)

1 month ago
UNKNOWNPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

1 month ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

1 month ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

1 month ago
UNKNOWNPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

1 month ago
HIGHPyPI

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

homeassistant: before 2026.6.0

1 month ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

1 month ago
CRITICALPyPI

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes: before 3.9.0

1 month ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

1 month ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

1 month ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

1 month ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

1 month ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

1 month ago
UNKNOWNPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

1 month ago
UNKNOWNPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

1 month ago
UNKNOWNPyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: all versions

1 month ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

1 month ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

1 month ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

1 month ago
MEDIUMPyPI

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

sglang: all versions

1 month ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

1 month ago
HIGHPyPI

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

libp2p: all versions

1 month ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

1 month ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

1 month ago
UNKNOWNPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

1 month ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

1 month ago
UNKNOWNPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

1 month ago
HIGHPyPI

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: before 0.22.0

1 month ago
UNKNOWNPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

1 month ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

1 month ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

1 month ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

1 month ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

1 month ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

1 month ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

1 month ago
UNKNOWNPyPI

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

jupyterlab: 3.3.0 → 4.5.10

1 month ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

1 month ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

1 month ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

1 month ago
UNKNOWNPyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

jupyterlab: before 4.5.10

1 month ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens: before 1.2.3

1 month ago
HIGHPyPI

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

mlflow: 2.14.0rc0 → 3.13.0rc0

1 month ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

1 month ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai: 1.65.0 → 1.106.0

1 month ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens-cli: before 1.2.3

1 month ago
UNKNOWNPyPI

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

jupyterlab: 4.5.0 → 4.5.10

1 month ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

1 month ago
UNKNOWNPyPI

Malicious code in libasync (PyPI)

Malicious code in libasync (PyPI)

1 month ago
HIGHPyPI

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

geolens: before 1.2.4

1 month ago
UNKNOWNPyPI

Malicious code in rc4-secure (PyPI)

Malicious code in rc4-secure (PyPI)

1 month ago
CRITICALPyPI

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

document-merge-service: before 9.1.0

1 month ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

1 month ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

1 month ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

1 month ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

1 month ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

1 month ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

1 month ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

1 month ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

1 month ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

1 month ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

1 month ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

1 month ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

1 month ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

1 month ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

1 month ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

1 month ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

1 month ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

1 month ago
HIGHPyPI

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

monai: before 1.6.0

1 month ago
CRITICALPyPI

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

monai: before 1.6.0

1 month ago
CRITICALPyPI

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

monai: before 1.6.0

1 month ago
UNKNOWNPyPI

Malicious code in deepface-weight (PyPI)

Malicious code in deepface-weight (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in deepface-weights (PyPI)

Malicious code in deepface-weights (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in reqcrypt (PyPI)

Malicious code in reqcrypt (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in httpz-requests (PyPI)

Malicious code in httpz-requests (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in infogram-bot (PyPI)

Malicious code in infogram-bot (PyPI)

1 month ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

openssl-encrypt: before 1.4.0

1 month ago
HIGHPyPI

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recover

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.

openssl-encrypt: before 1.4.0

1 month ago
MODERATEPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

1 month ago
HIGHPyPI

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.

openssl-encrypt: before 1.4.0

1 month ago
HIGHPyPI

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost.

openssl-encrypt: before 1.4.6

1 month ago
HIGHPyPI

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: before 1.1.0

1 month ago
UNKNOWNPyPI

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hs

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to

openssl-encrypt: before 1.4.7

1 month ago
HIGHPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

1 month ago
HIGHPyPI

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: before 1.1.0

1 month ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

1 month ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

1 month ago
HIGHPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

1 month ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

1 month ago
HIGHPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

1 month ago
HIGHPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: 3.3.0 → 3.15.0

1 month ago
HIGHPyPI

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.

openssl-encrypt: before 1.4.0

1 month ago
HIGHPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

1 month ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.

openssl-encrypt: before 1.4.0

1 month ago
UNKNOWNPyPI

Malicious code in kb-ai (PyPI)

Malicious code in kb-ai (PyPI)

1 month ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

1 month ago
HIGHPyPI

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: before 1.1.0

1 month ago
UNKNOWNPyPI

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.

gitpython: before 3.1.55

1 month ago
UNKNOWNPyPI

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing.

gitpython: before 3.1.56

1 month ago
UNKNOWNPyPI

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.

gitpython: before 3.1.57

1 month ago
CRITICALPyPI

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

gitpython: before 3.1.54

1 month ago
UNKNOWNPyPI

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

gitpython: before 3.1.57

1 month ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

1 month ago
UNKNOWNPyPI

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

gitpython: before 3.1.54

1 month ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

1 month ago
HIGHPyPI

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: before 3.10.0

1 month ago
HIGHPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

1 month ago
HIGHPyPI

Apache Airflow Task SDK fails to mask list-shaped JSON Variables

Apache Airflow Task SDK fails to mask list-shaped JSON Variables

apache-airflow: before 3.3.1

1 month ago
HIGHPyPI

Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass

Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow Variables UI fails to mask sensitive values in deeply nested iterables

Apache Airflow Variables UI fails to mask sensitive values in deeply nested iterables

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs

Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

1 month ago
HIGHPyPI

Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext

Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds

apache-airflow: 3.3.0 → 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n

apache-airflow: before 3.3.1

1 month ago
CRITICALPyPI

Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler

Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore

apache-airflow: before 3.3.1

1 month ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

1 month ago
HIGHPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

1 month ago
HIGHPyPI

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus

apache-airflow-providers-google: before 22.3.0

1 month ago
MEDIUMPyPI

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m

apache-airflow: before 3.3.1

1 month ago
HIGHPyPI

Apache Airflow Config API exposes team-scoped sensitive configuration values

Apache Airflow Config API exposes team-scoped sensitive configuration values

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option na

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulte

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgr

apache-airflow: before 3.3.1

1 month ago
HIGHPyPI

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

apache-airflow: before 3.3.1

1 month ago
CRITICALPyPI

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. T

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat

apache-airflow: before 3.3.1

1 month ago
CRITICALPyPI

Apache Airflow exception-node deserialization permits arbitrary callable execution

Apache Airflow exception-node deserialization permits arbitrary callable execution

apache-airflow: 3.3.0 → 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow environment-variable secrets backend permits cross-team credential use

Apache Airflow environment-variable secrets backend permits cross-team credential use

apache-airflow: before 3.3.1

1 month ago
CRITICALPyPI

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce

apache-airflow: 3.3.0 → 3.3.1

1 month ago
HIGHPyPI

Apache Airflow exposes dict-valued var.json secrets in Rendered Templates

Apache Airflow exposes dict-valued var.json secrets in Rendered Templates

apache-airflow: before 3.3.1

1 month ago
HIGHPyPI

Apache Airflow missing team context permits cross-team Dag actions and XCom reads

Apache Airflow missing team context permits cross-team Dag actions and XCom reads

apache-airflow: before 3.3.1

1 month ago
MEDIUMPyPI

Apache Airflow XCom API permits unsafe deserialization through JSON string literals

Apache Airflow XCom API permits unsafe deserialization through JSON string literals

apache-airflow: before 3.3.1

1 month ago
UNKNOWNPyPI

Malicious code in dlmm (PyPI)

Malicious code in dlmm (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in telebot-pro (PyPI)

Malicious code in telebot-pro (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in morpho-sdk (PyPI)

Malicious code in morpho-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in euler-sdk (PyPI)

Malicious code in euler-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in joule-btp-extension (PyPI)

Malicious code in joule-btp-extension (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in joule-sbx-poc (PyPI)

Malicious code in joule-sbx-poc (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in dlmm-sdk (PyPI)

Malicious code in dlmm-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in btcflip (PyPI)

Malicious code in btcflip (PyPI)

1 month ago
HIGHPyPI

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

keras: before 3.15.0

1 month ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-sqlite: before 3.1.1

1 month ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-postgres: before 3.1.1

1 month ago
UNKNOWNPyPI

Malicious code in plp-contract (PyPI)

Malicious code in plp-contract (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kotoraka (PyPI)

Malicious code in kotoraka (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in neutrl-core (PyPI)

Malicious code in neutrl-core (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in btcflx (PyPI)

Malicious code in btcflx (PyPI)

1 month ago
HIGHPyPI

Apache Airflow Yandex Lockbox backend allows cross-team secret disclosure

Apache Airflow Yandex Lockbox backend allows cross-team secret disclosure

apache-airflow-providers-yandex: before 4.5.1

1 month ago
HIGHPyPI

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

accelerate: all versions

1 month ago
HIGHPyPI

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe

apache-airflow-providers-yandex: before 4.5.1

1 month ago

Tooling for PyPI

Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPackagistPubRubyGemsSwiftURLcrates.ionpm