PyPI incidents

Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNPyPI

Malicious code in chroma-client (PyPI)

Malicious code in chroma-client (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in python-fork (PyPI)

Malicious code in python-fork (PyPI)

3 days ago
CRITICALPyPI

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)

mysql-mcp-server: before 0.4.2

4 days ago
UNKNOWNPyPI

Malicious code in platform-telemetry-client (PyPI)

Malicious code in platform-telemetry-client (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in langgrap (PyPI)

Malicious code in langgrap (PyPI)

4 days ago
HIGHPyPI

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover

prowler-cloud: before 5.30.3

4 days ago
UNKNOWNPyPI

Malicious code in eth-account-web3 (PyPI)

Malicious code in eth-account-web3 (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in ollamaa (PyPI)

Malicious code in ollamaa (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in aitextutils-py (PyPI)

Malicious code in aitextutils-py (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in openaii (PyPI)

Malicious code in openaii (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in web3-eth-account (PyPI)

Malicious code in web3-eth-account (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in aitextkit-py (PyPI)

Malicious code in aitextkit-py (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in transfomers (PyPI)

Malicious code in transfomers (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in pymem-win (PyPI)

Malicious code in pymem-win (PyPI)

4 days ago
MEDIUMPyPI

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

open-webui: 0.9.5 → 0.11.1

5 days ago
CRITICALPyPI

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

compliance-trestle: before 3.12.4

5 days ago
HIGHPyPI

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

gitpython: before 3.1.59

5 days ago
HIGHPyPI

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh: before 2.23.1

5 days ago
UNKNOWNPyPI

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

lightning: before 1.6.0

5 days ago
HIGHPyPI

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

thrift: before 0.24.0

5 days ago
UNKNOWNPyPI

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

chromadb: ≥ 0.4.17

5 days ago
HIGHPyPI

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

ironic: 17.0.0 → 29.0.6

5 days ago
UNKNOWNPyPI

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: before 0.6.0

5 days ago
UNKNOWNPyPI

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents: 1.5.128 → 1.6.58

5 days ago
HIGHPyPI

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vllm: before 0.26.0

5 days ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

open-webui: 0.10.0 → 0.11.1

5 days ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

5 days ago
HIGHPyPI

ONNX: TOCTOU arbitrary file read/write in save_external_dat

ONNX: TOCTOU arbitrary file read/write in save_external_dat

onnx: before 1.21.0

5 days ago
HIGHPyPI

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

praisonai: before 4.6.58

5 days ago
HIGHPyPI

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents: before 1.6.58

5 days ago
UNKNOWNPyPI

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

copier: 9.5.0 → 9.15.2

5 days ago
UNKNOWNPyPI

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

lightning: before 1.6.0

5 days ago
HIGHPyPI

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

httpx2: before 2.12.0

5 days ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

5 days ago
HIGHPyPI

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

praisonai: before 4.6.58

5 days ago
UNKNOWNPyPI

Snowflake Connector for Python improperly verifies TLS hostnames

Snowflake Connector for Python improperly verifies TLS hostnames

snowflake-connector-python: before 3.18.1

5 days ago
CRITICALPyPI

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

chromadb: ≥ 0.5.0

5 days ago
UNKNOWNPyPI

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vllm: 0.21.0 → 0.26.0

5 days ago
MEDIUMPyPI

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

praisonai: before 4.6.58

5 days ago
MEDIUMPyPI

PyOD persistence.load deserializes untrusted artifacts before validation

PyOD persistence.load deserializes untrusted artifacts before validation

pyod: 3.5.0 → 3.6.2

5 days ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql: before 1.1.1

5 days ago
MEDIUMPyPI

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

githacker: before 1.1.8

5 days ago
MEDIUMPyPI

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

open-webui: 0.9.5 → 0.11.1

5 days ago
HIGHPyPI

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

praisonai: before 4.6.58

5 days ago
HIGHPyPI

MLflow AI Gateway permits SSRF through an unvalidated api_base

MLflow AI Gateway permits SSRF through an unvalidated api_base

mlflow: ≥ 3.13.0

5 days ago
HIGHPyPI

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

keras: before 3.15.0

5 days ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler-cloud: before 5.37.0

5 days ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-websocket: before 1.1.1

5 days ago
CRITICALPyPI

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp: before 0.2.1

5 days ago
UNKNOWNPyPI

Malicious code in lucy-python-script-2030 (PyPI)

Malicious code in lucy-python-script-2030 (PyPI)

5 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: before 6.16.1

5 days ago
UNKNOWNPyPI

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

justhtml: before 1.10.0

5 days ago
HIGHPyPI

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

pytorch-lightning: before 2.3.3

5 days ago
HIGHPyPI

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

praisonai: before 4.6.58

5 days ago
HIGHPyPI

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

nltk: before 3.10.1

5 days ago
MEDIUMPyPI

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy-mini: before 1.8.2

5 days ago
HIGHPyPI

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

praisonai: before 4.6.58

5 days ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: before 6.16.1

5 days ago
UNKNOWNPyPI

Windows ML CLI: CORS misconfig enables localhost RCE

Windows ML CLI: CORS misconfig enables localhost RCE

winml-cli: before 0.4.0

5 days ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.9.0

5 days ago
HIGHPyPI

Cognee allows non-superusers to overwrite global LLM configuration

Cognee allows non-superusers to overwrite global LLM configuration

cognee: before 1.5.0

5 days ago
MEDIUMPyPI

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

open-webui: 0.7.0 → 0.11.1

5 days ago
CRITICALPyPI

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

xinference: before 2.7.0

5 days ago
HIGHPyPI

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

thrift: before 0.24.0

5 days ago
HIGHPyPI

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: before 0.117.2

5 days ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

open-webui: 0.8.11 → 0.11.1

5 days ago
HIGHPyPI

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

praisonai: 4.6.34 → 4.6.58

5 days ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonai: 3.9.26 → 4.6.58

5 days ago
UNKNOWNPyPI

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

praisonai: before 4.6.58

5 days ago
MEDIUMPyPI

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

weblate: before 2026.7

5 days ago
CRITICALPyPI

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite-core: ≥ 2.0.0

5 days ago
HIGHPyPI

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

praisonai: before 4.6.58

5 days ago
MEDIUMPyPI

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

chainlit: 2.4.0rc0 → 2.12.0

5 days ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

open-webui: 0.5.0 → 0.11.1

5 days ago
HIGHPyPI

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents: before 1.6.58

5 days ago
CRITICALPyPI

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite

open-webui: 0.6.41 → 0.11.1

5 days ago
UNKNOWNPyPI

Malicious code in pylever (PyPI)

Malicious code in pylever (PyPI)

5 days ago
CRITICALPyPI

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

gitpython: before 3.1.58

5 days ago
HIGHPyPI

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

transformers: before 5.10.0

5 days ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

5 days ago
HIGHPyPI

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust: before 1.0.4

5 days ago
CRITICALPyPI

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

gitpython: before 3.1.58

5 days ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

5 days ago
HIGHPyPI

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents: before 1.6.58

5 days ago
MEDIUMPyPI

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

nltk: before 3.10.3

5 days ago
MEDIUMPyPI

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

kas: before 5.4

5 days ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpcore2: before 2.10.0

5 days ago
HIGHPyPI

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents: before 1.6.58

5 days ago
MEDIUMPyPI

Material for MkDocs: DOM XSS in search suggestions via query parameter

Material for MkDocs: DOM XSS in search suggestions via query parameter

mkdocs-material: 7.2.0 → 9.7.7

5 days ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpx2: 2.6.0 → 2.10.0

5 days ago
CRITICALPyPI

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

esphome-device-builder: before 1.0.10

5 days ago
UNKNOWNPyPI

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

wsgidav: before 4.3.5

5 days ago
HIGHPyPI

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

httpx2: 2.5.0 → 2.10.0

5 days ago
MEDIUMPyPI

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vllm: before 0.26.0

5 days ago
HIGHPyPI

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

open-webui: before 0.11.1

5 days ago
MEDIUMPyPI

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

sqladmin: before 0.27.1

5 days ago
MEDIUMPyPI

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

httpx2: before 2.11.0

5 days ago
CRITICALPyPI

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

nltk: before 3.10.3

5 days ago
HIGHPyPI

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

thrift: before 0.24.0

5 days ago
UNKNOWNPyPI

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: before 6.16.0

5 days ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

5 days ago
CRITICALPyPI

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway: before 1.0.2

5 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

open-webui: 0.10.0 → 0.11.1

5 days ago
HIGHPyPI

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

restrictedpython: before 8.3

5 days ago
CRITICALPyPI

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

gitpython: before 3.1.51

5 days ago
CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

gitpython: before 3.1.51

5 days ago
HIGHPyPI

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

open-webui: 0.9.6 → 0.11.1

5 days ago
HIGHPyPI

asteval has a Sandbox Escape via BaseException Subclasses

asteval has a Sandbox Escape via BaseException Subclasses

asteval: before 1.0.9

5 days ago
HIGHPyPI

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone-app-portlets: before 5.0.8

5 days ago
HIGHPyPI

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

icalendar: 7.1.0 → 7.1.3

5 days ago
MEDIUMPyPI

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

open-webui: 0.8.0 → 0.11.1

5 days ago
HIGHPyPI

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools: before 1.15.1

5 days ago
UNKNOWNPyPI

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

nltk: before 3.10.3

5 days ago
HIGHPyPI

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

open-webui: 0.9.0 → 0.11.1

5 days ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-checkpoint-mongodb: before 0.3.0

5 days ago
CRITICALPyPI

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

litellm: before 1.83.7

5 days ago
HIGHPyPI

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: before 0.10.0

5 days ago
CRITICALPyPI

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

document-merge-service: before 9.1.0

5 days ago
HIGHPyPI

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

mistune: 3.3.0 → 3.3.3

5 days ago
HIGHPyPI

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

apache-airflow: before 3.3.0

5 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

open-webui: 0.9.0 → 0.11.1

5 days ago
HIGHPyPI

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

praisonai: before 4.6.58

5 days ago
HIGHPyPI

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

plone-app-event: before 5.2.4

5 days ago
CRITICALPyPI

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

lightning: all versions

5 days ago
HIGHPyPI

PyTorch Lightning denial of service vulnerability

PyTorch Lightning denial of service vulnerability

lightning: all versions

5 days ago
HIGHPyPI

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

snowflake-sqlalchemy: 1.1.6 → 1.11.0

5 days ago
UNKNOWNPyPI

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: before 6.15.0

5 days ago
HIGHPyPI

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

scrapy: before 2.17.0

5 days ago
CRITICALPyPI

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed: before 5.1.2

5 days ago
HIGHPyPI

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

open-webui: 0.10.0 → 0.11.1

5 days ago
HIGHPyPI

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

gitpython: before 3.1.58

5 days ago
HIGHPyPI

aiosmtplib: STARTTLS response injection

aiosmtplib: STARTTLS response injection

aiosmtplib: before 5.1.2

5 days ago
HIGHPyPI

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh: before 2.23.1

5 days ago
MEDIUMPyPI

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml-parser: before 3.0.2

5 days ago
HIGHPyPI

PyTorch Lightning path traversal vulnerability

PyTorch Lightning path traversal vulnerability

lightning: before 2.4.0

5 days ago
MEDIUMPyPI

OpenHarness remote project-context commands allow persistent prompt poisoning

OpenHarness remote project-context commands allow persistent prompt poisoning

openharness-ai: all versions

5 days ago
MEDIUMPyPI

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vllm: before 0.26.0

5 days ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-store-mongodb: before 0.4.0

5 days ago
HIGHPyPI

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

eml-parser: before 3.0.2

5 days ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

5 days ago
MEDIUMPyPI

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

jupyterhub: before 5.5.0

5 days ago
CRITICALPyPI

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

chromadb: ≥ 0.4.17

5 days ago
MEDIUMPyPI

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

open-webui: 0.10.0 → 0.11.1

5 days ago
CRITICALPyPI

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

omnigent: before 0.3.0

5 days ago
CRITICALPyPI

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

omnigent: before 0.3.0

5 days ago
HIGHPyPI

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout

open-webui: 0.9.0 → 0.11.1

5 days ago
HIGHPyPI

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

tornado: before 6.5.8

5 days ago
HIGHPyPI

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: before 1.6.58

5 days ago
CRITICALPyPI

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

nltk: 3.10.0 → 3.10.3

5 days ago
HIGHPyPI

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

praisonai: before 4.6.58

5 days ago
UNKNOWNPyPI

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

protego: before 0.6.2

5 days ago
CRITICALPyPI

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

chainlit: 2.4.0rc0 → 2.12.0

5 days ago
HIGHPyPI

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: 0.4.7 → 0.24.0

5 days ago
UNKNOWNPyPI

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

banks: before 2.4.5

5 days ago
CRITICALPyPI

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

hydra-core: before 1.3.4

5 days ago
HIGHPyPI

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

weblate: before 2026.7

5 days ago
CRITICALPyPI

Compromise of PyTorch Lightning PyPi Package Versions

Compromise of PyTorch Lightning PyPi Package Versions

lightning: 2.6.2 → 2.6.4

5 days ago
HIGHPyPI

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: before 0.10.0

5 days ago
HIGHPyPI

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml-parser: before 3.0.2

5 days ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

wagtail: before 7.0.9

5 days ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

5 days ago
MEDIUMPyPI

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

httpx2: before 2.11.0

5 days ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler: before 5.37.0

5 days ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

5 days ago
CRITICALPyPI

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

omnigent: before 0.3.0

5 days ago
MEDIUMPyPI

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

webob: before 1.8.11

5 days ago
CRITICALPyPI

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin: before 1.14.0

5 days ago
MEDIUMPyPI

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

starlette-admin: before 0.16.1

5 days ago
CRITICALPyPI

Remote code execution in pytorch lightning

Remote code execution in pytorch lightning

pytorch-lightning: before 2.3.3

5 days ago
HIGHPyPI

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

gitpython: before 3.1.58

5 days ago
MEDIUMPyPI

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vllm: before 0.26.0

5 days ago
HIGHPyPI

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

omnigent: before 0.3.0

5 days ago
HIGHPyPI

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

gitpython: before 3.1.52

5 days ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonaiagents: 0.12.12 → 1.6.58

5 days ago
HIGHPyPI

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

praisonai: before 4.6.58

5 days ago
HIGHPyPI

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

accelerate: all versions

5 days ago
HIGHPyPI

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

open-webui: 0.6.27 → 0.11.1

5 days ago
HIGHPyPI

vLLM: Cross-User Data Leak Vulnerability

vLLM: Cross-User Data Leak Vulnerability

vllm: before 0.27.0

5 days ago
HIGHPyPI

OpenHarness remote resume commands expose other users' saved session snapshots

OpenHarness remote resume commands expose other users' saved session snapshots

openharness-ai: all versions

5 days ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

5 days ago
HIGHPyPI

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: before 1.6.58

5 days ago
HIGHPyPI

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint: before 70.0

5 days ago
CRITICALPyPI

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

esphome-device-builder: before 1.0.10

6 days ago
MEDIUMPyPI

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`

sqladmin: before 0.27.1

6 days ago
UNKNOWNPyPI

Malicious code in websetup (PyPI)

Malicious code in websetup (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in bq-build-probe-vrp-2026 (PyPI)

Malicious code in bq-build-probe-vrp-2026 (PyPI)

6 days ago
UNKNOWNPyPI

Malicious code in databricks-webapp-navigation-homepage (PyPI)

Malicious code in databricks-webapp-navigation-homepage (PyPI)

6 days ago
HIGHPyPI

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint Has Server-Side Request Forgery (SSRF)

weasyprint: before 70.0

6 days ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

Open WebUI: Any authenticated user can hang the server via a cyclic chat message history

open-webui: 0.5.0 → 0.11.1

6 days ago
MEDIUMPyPI

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets

open-webui: 0.9.5 → 0.11.1

6 days ago
UNKNOWNPyPI

Malicious code in bq-sdist-probe-vrp (PyPI)

Malicious code in bq-sdist-probe-vrp (PyPI)

6 days ago
HIGHPyPI

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree

open-webui: 0.10.0 → 0.11.1

6 days ago
MEDIUMPyPI

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

githacker: before 1.1.8

6 days ago
HIGHPyPI

NLTK: Stable FrameNet and NKJP readers parse outside-root XML

NLTK: Stable FrameNet and NKJP readers parse outside-root XML

nltk: before 3.10.0

1 week ago
HIGHPyPI

NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions

nltk: before 3.10.0

1 week ago
HIGHPyPI

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

nltk: before 3.9.3

1 week ago
MEDIUMPyPI

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers

httpx2: before 2.11.0

1 week ago
HIGHPyPI

NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root

nltk: before 3.9.4

1 week ago
CRITICALPyPI

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

gitpython: before 3.1.59

1 week ago
HIGHPyPI

NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read

nltk: before 3.10.0

1 week ago
CRITICALPyPI

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

nltk: before 3.10.3

1 week ago
HIGHPyPI

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

gitpython: before 3.1.59

1 week ago
HIGHPyPI

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

HTTPX2: Quadratic SSE line buffering can cause CPU denial of service

httpx2: 2.5.0 → 2.10.0

1 week ago
HIGHPyPI

NLTK: Corpus Reader Sandbox Bypass

NLTK: Corpus Reader Sandbox Bypass

nltk: before 3.10.3

1 week ago
HIGHPyPI

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

gitpython: before 3.1.59

1 week ago
HIGHPyPI

NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

nltk: before 3.10.3

1 week ago
HIGHPyPI

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

nltk: 3.10.0 → 3.10.2

1 week ago
CRITICALPyPI

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

nltk: before 3.10.0

1 week ago
HIGHPyPI

NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol

nltk: before 3.10.0

1 week ago
MODERATEPyPI

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks

nltk: before 3.10.3

1 week ago
HIGHPyPI

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

nltk: before 3.10.3

1 week ago
HIGHPyPI

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

gitpython: before 3.1.59

1 week ago
HIGHPyPI

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

nltk: before 3.10.3

1 week ago
HIGHPyPI

vLLM: Cross-User Data Leak Vulnerability

vLLM: Cross-User Data Leak Vulnerability

vllm: before 0.27.0

1 week ago
CRITICALPyPI

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

gitpython: before 3.1.59

1 week ago
HIGHPyPI

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

vllm: before 0.26.0

1 week ago
HIGHPyPI

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)

httpx2: before 2.12.0

1 week ago
HIGHPyPI

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

nltk: 3.10.0 → 3.10.2

1 week ago
HIGHPyPI

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

nltk: before 3.10.3

1 week ago
HIGHPyPI

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies

httpcore2: before 2.10.0

1 week ago
HIGHPyPI

Windows ML CLI: CORS misconfig enables localhost RCE

Windows ML CLI: CORS misconfig enables localhost RCE

winml-cli: before 0.4.0

1 week ago
MEDIUMPyPI

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

prowler: before 5.37.0

1 week ago
MEDIUMPyPI

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated

httpx2: before 2.11.0

1 week ago
UNKNOWNPyPI

Malicious code in cv-train (PyPI)

Malicious code in cv-train (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in telegram-helper (PyPI)

Malicious code in telegram-helper (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in dac-tools (PyPI)

Malicious code in dac-tools (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in minecraftmodes (PyPI)

Malicious code in minecraftmodes (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in dbt-sa-cli (PyPI)

Malicious code in dbt-sa-cli (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in proxycer (PyPI)

Malicious code in proxycer (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in trongridew (PyPI)

Malicious code in trongridew (PyPI)

1 week ago
MEDIUMPyPI

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

vllm: before 0.26.0

1 week ago
MEDIUMPyPI

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

vllm: before 0.26.0

1 week ago
UNKNOWNPyPI

Malicious code in astlsi (PyPI)

Malicious code in astlsi (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in houdus (PyPI)

Malicious code in houdus (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in tsshare (PyPI)

Malicious code in tsshare (PyPI)

tsshare: all versions

1 week ago
UNKNOWNPyPI

Malicious code in tpu-raiden-jax (PyPI)

Malicious code in tpu-raiden-jax (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in pymaas (PyPI)

Malicious code in pymaas (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in metricboxlite (PyPI)

Malicious code in metricboxlite (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in chartkit-core (PyPI)

Malicious code in chartkit-core (PyPI)

1 week ago
MODERATEPyPI

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

vllm: 0.21.0 → 0.26.0

1 week ago
UNKNOWNPyPI

Malicious code in timeweave (PyPI)

Malicious code in timeweave (PyPI)

1 week ago
MEDIUMPyPI

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

vllm: before 0.26.0

1 week ago
UNKNOWNPyPI

Malicious code in olympuslib (PyPI)

Malicious code in olympuslib (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in qoeoe (PyPI)

Malicious code in qoeoe (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in 0requests (PyPI)

Malicious code in 0requests (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in py-1requests (PyPI)

Malicious code in py-1requests (PyPI)

1 week ago
MEDIUMPyPI

Material for MkDocs: DOM XSS in search suggestions via query parameter

Material for MkDocs: DOM XSS in search suggestions via query parameter

mkdocs-material: 7.2.0 → 9.7.7

1 week ago
HIGHPyPI

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: Server-Side Request Forgery in the URL-based partitioning

unstructured: 0.4.7 → 0.24.0

1 week ago
UNKNOWNPyPI

Malicious code in company-sdk (PyPI)

Malicious code in company-sdk (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in py-0requests (PyPI)

Malicious code in py-0requests (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in uvhttp-custom (PyPI)

Malicious code in uvhttp-custom (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in asti (PyPI)

Malicious code in asti (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in env-validator-tool (PyPI)

Malicious code in env-validator-tool (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in telemetry-helper (PyPI)

Malicious code in telemetry-helper (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in py-2equests (PyPI)

Malicious code in py-2equests (PyPI)

1 week ago
UNKNOWNPyPI

Malicious code in trongridi (PyPI)

Malicious code in trongridi (PyPI)

1 week ago
HIGHPyPI

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

nltk: before 3.10.3

1 week ago
HIGHPyPI

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

mistune: 3.3.0 → 3.3.3

1 week ago
HIGHPyPI

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py

omnigent: before 0.3.0

1 week ago
HIGHPyPI

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

nltk: all versions

1 week ago
MEDIUMPyPI

NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

NLTK: Uncontrolled recursion in nltk.featstruct.FeatStructReader causes unhandled RecursionError (DoS) via deeply nested feature-structure input

nltk: before 3.10.3

1 week ago
CRITICALPyPI

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE

omnigent: before 0.3.0

1 week ago
MEDIUMPyPI

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`

nltk: before 3.10.3

1 week ago
MODERATEPyPI

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace

pypdf: before 6.15.0

1 week ago
MODERATEPyPI

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

nltk: before 3.10.3

1 week ago
CRITICALPyPI

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE

omnigent: before 0.3.0

1 week ago
HIGHPyPI

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

tornado: before 6.5.8

1 week ago
HIGHPyPI

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default

scrapy: before 2.17

1 week ago
MODERATEPyPI

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure

nltk: before 3.10.0

1 week ago
HIGHPyPI

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

nltk: before 3.10.0

1 week ago
CRITICALPyPI

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools

omnigent: before 0.3.0

1 week ago
MODERATEPyPI

NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'

NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y'

nltk: before 3.10.3

1 week ago
MEDIUMPyPI

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generat

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web

pyspark: 3.0.0 → 3.5.8

1 week ago
MODERATEPyPI

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

banks: before 2.4.5

1 week ago
MODERATEPyPI

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: Possible infinite loop for TreeObject.insert_child

pypdf: before 6.16.0

2 weeks ago
CRITICALPyPI

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

nltk: before 3.10.3

2 weeks ago
CRITICALPyPI

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

mlflow: 2.1.0 → 3.15.0

2 weeks ago
UNKNOWNPyPI

Malicious code in gcphelpit (PyPI)

Malicious code in gcphelpit (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in syswatch (PyPI)

Malicious code in syswatch (PyPI)

2 weeks ago
LOWPyPI

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

tornado: 6.5.5 → 6.5.8

2 weeks ago
CRITICALPyPI

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

nltk: before 3.10.3

2 weeks ago
MEDIUMPyPI

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

djangorestframework: before 3.17.2

2 weeks ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: Possible long runtimes/large memory usage when extracting XForm objects

pypdf: before 6.16.1

2 weeks ago
UNKNOWNPyPI

Malicious code in tallyboxlite (PyPI)

Malicious code in tallyboxlite (PyPI)

2 weeks ago
MODERATEPyPI

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: before 6.5.8

2 weeks ago
MODERATEPyPI

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption

sqlparse: before 0.6.0

2 weeks ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: Possible long runtimes/large memory usage when retrieving outlines

pypdf: before 6.16.1

2 weeks ago
MEDIUMPyPI

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

djangorestframework: before 3.17.2

2 weeks ago
UNKNOWNPyPI

Malicious code in pyservercheck (PyPI)

Malicious code in pyservercheck (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in trongridor (PyPI)

Malicious code in trongridor (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in tronlinker (PyPI)

Malicious code in tronlinker (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in auth-app-streamlit (PyPI)

Malicious code in auth-app-streamlit (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in flask-header-guard (PyPI)

Malicious code in flask-header-guard (PyPI)

2 weeks ago
HIGHPyPI

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

restrictedpython: before 8.3

2 weeks ago
UNKNOWNPyPI

Malicious code in yaml-report-formatter (PyPI)

Malicious code in yaml-report-formatter (PyPI)

2 weeks ago
CRITICALPyPI

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

compliance-trestle: before 3.12.4

2 weeks ago
HIGHPyPI

plone.app.event vulnerable to denial of service via iCalendar import

plone.app.event vulnerable to denial of service via iCalendar import

plone-app-event: before 5.2.4

2 weeks ago
HIGHPyPI

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

protego: before 0.6.2

2 weeks ago
CRITICALPyPI

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin: before 1.14.0

2 weeks ago
HIGHPyPI

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

weblate: before 2026.7

2 weeks ago
UNKNOWNPyPI

Malicious code in calcboxlite (PyPI)

Malicious code in calcboxlite (PyPI)

2 weeks ago
MODERATEPyPI

AIIR verification and policy gates could report success without enforcing the control (fail-open)

AIIR verification and policy gates could report success without enforcing the control (fail-open)

aiir: before 1.7.0

2 weeks ago
MEDIUMPyPI

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

weblate: before 2026.7

2 weeks ago
HIGHPyPI

WsgiDAV MySQL provider has a blind SQL injection

WsgiDAV MySQL provider has a blind SQL injection

wsgidav: before 4.3.5

2 weeks ago
UNKNOWNPyPI

Malicious code in yamlformatter-utils (PyPI)

Malicious code in yamlformatter-utils (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in yamlformat-tools (PyPI)

Malicious code in yamlformat-tools (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in pygame-renderkit (PyPI)

Malicious code in pygame-renderkit (PyPI)

2 weeks ago
HIGHPyPI

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone.app.portlets vulnerable to denial of service via RSS feed portlet

plone-app-portlets: 7.0.0 → 7.0.2

2 weeks ago
UNKNOWNPyPI

Malicious code in mathkitlite (PyPI)

Malicious code in mathkitlite (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in flyteplugins-echo (PyPI)

Malicious code in flyteplugins-echo (PyPI)

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

Malicious code in flyteplugins-agento11y (PyPI)

Malicious code in flyteplugins-agento11y (PyPI)

2 weeks ago
UNKNOWNPyPI

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names, --option=value forms, and tokens starting with -p, so these spellings bypass the redaction chokepoint and the cleartext password is written to stderr. Anyone with access to that output (terminal scrollback, merged 2>&1 output,

openssl-encrypt: before 1.4.9

2 weeks ago
MEDIUMPyPI

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.

openssl-encrypt: before 1.4.9

2 weeks ago
HIGHPyPI

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.

openssl-encrypt: before 1.4.9

2 weeks ago
MEDIUMPyPI

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

netron: before 9.1.3

2 weeks ago
UNKNOWNPyPI

Malicious code in ekx-report-utils (PyPI)

Malicious code in ekx-report-utils (PyPI)

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster than documented protection by exploiting the missing key stretching and hash rounds.

openssl-encrypt: before 1.4.9

2 weeks ago
HIGHPyPI

aiosmtplib: STARTTLS response injection

aiosmtplib: STARTTLS response injection

aiosmtplib: before 5.1.2

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offline password guessing at hardware speed to recover user passwords.

openssl-encrypt: before 1.4.9

2 weeks ago
CRITICALPyPI

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the printed CLI block into a shell.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

Malicious code in flyteplugins-nsight (PyPI)

Malicious code in flyteplugins-nsight (PyPI)

2 weeks ago
UNKNOWNPyPI

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement and erase-line control bytes that repaint a forged PASSED verdict on screen, masking actual tamper detection. Fixed in 1.4.9 by routing drive-derived names through sanitize_for_display().

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main password. Any local user can read the steganography password from /proc/<pid>/cmdline for the lifetime of the subprocess. Fixed in 1.4.9.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

nltk: before 3.10.3

2 weeks ago
CRITICALPyPI

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

litellm: before 1.83.7

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false integrity verification.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a result the token is printed in cleartext to stderr under --debug (even without --unsafe-show-secrets), persisting the credential in logs and terminal history. Fixed in 1.4.9.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python's recursion limit and raise an unhandled RecursionError, crashing applications that parse user-supplied feature structures or feature grammars.

nltk: before 3.10.3

2 weeks ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.

nltk: before 3.10.3

2 weeks ago
UNKNOWNPyPI

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y' characters on every call, and _measure() invokes it for each stem position, causing O(n^2) behavior. A single ~20-50 KB untrusted token consisting of a long run of the letter 'y' followed by a matching suffix (e.g., 'ness') can pin a CPU core for seconds to minutes, causin

nltk: before 3.10.3

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths to achieve arbitrary code execution in the CLI process with access to passwords and cryptographic keys.

openssl-encrypt: before 1.4.9

2 weeks ago
UNKNOWNPyPI

Malicious code in sap-quarterly-report (PyPI)

Malicious code in sap-quarterly-report (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in flyteplugins-redis (PyPI)

Malicious code in flyteplugins-redis (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in decoris (PyPI)

Malicious code in decoris (PyPI)

2 weeks ago
UNKNOWNPyPI

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

nltk: before 3.10.3

2 weeks ago
MEDIUMPyPI

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

webob: before 1.8.11

2 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.

nltk: before 3.10.0

2 weeks ago
MEDIUMPyPI

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

starlette-admin: before 0.16.1

2 weeks ago
UNKNOWNPyPI

Malicious code in pybitjs (PyPI)

Malicious code in pybitjs (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in trongridet (PyPI)

Malicious code in trongridet (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in syntaxerror-package-12345 (PyPI)

Malicious code in syntaxerror-package-12345 (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in 0xfighter3 (PyPI)

Malicious code in 0xfighter3 (PyPI)

2 weeks ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation or timeout. An attacker who controls the tgrep pattern (e.g., via tgrep_positions() or tgrep_compile() exposed to external input) can supply a pattern that triggers catastrophic backtracking, causing i

nltk: before 3.10.3

2 weeks ago
MEDIUMPyPI

kas Persistently Disables SSH Host Key Checking

kas Persistently Disables SSH Host Key Checking

kas: before 5.4

2 weeks ago
UNKNOWNPyPI

Malicious code in bigquery-agent-analytics-tracing (PyPI)

Malicious code in bigquery-agent-analytics-tracing (PyPI)

2 weeks ago
CRITICALPyPI

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

pantheon-agents: 0.6.1 → 0.6.4

2 weeks ago
UNKNOWNPyPI

Malicious code in rce-test (PyPI)

Malicious code in rce-test (PyPI)

2 weeks ago
HIGHPyPI

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses

openwisp-ipam: before 1.2.1

2 weeks ago
HIGHPyPI

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

asyncssh: before 2.23.1

2 weeks ago
CRITICALPyPI

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite.core Vulnerable to Eval Injection and Missing Authorization

senaite-core: ≥ 2.0.0

2 weeks ago
HIGHPyPI

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh: before 2.23.1

2 weeks ago
MEDIUMPyPI

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy-mini: before 1.8.2

3 weeks ago
HIGHPyPI

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

praisonaiagents: before 1.6.58

3 weeks ago
MEDIUMPyPI

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql: before 1.1.1

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing denial of service.

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http: before 1.1.4

3 weeks ago
CRITICALPyPI

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp: before 0.2.1

3 weeks ago
UNKNOWNPyPI

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http: before 1.1.4

3 weeks ago
UNKNOWNPyPI

Malicious code in minecraft-ytreceiver (PyPI)

Malicious code in minecraft-ytreceiver (PyPI)

3 weeks ago
HIGHPyPI

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

praisonai: 4.6.34 → 4.6.58

3 weeks ago
UNKNOWNPyPI

Malicious code in python-walletlibr-v (PyPI)

Malicious code in python-walletlibr-v (PyPI)

3 weeks ago
HIGHPyPI

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway: before 1.0.0

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attack

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.

nltk: before 3.10.3

3 weeks ago
MEDIUMPyPI

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

praisonai: before 4.6.58

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: before 1.6.58

3 weeks ago
MEDIUMPyPI

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml-parser: before 3.0.2

3 weeks ago
HIGHPyPI

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.

uff: all versions

3 weeks ago
MEDIUMPyPI

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

chainlit: 2.4.0rc0 → 2.12.0

3 weeks ago
HIGHPyPI

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

praisonai: before 4.6.58

3 weeks ago
CRITICALPyPI

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

chainlit: 2.4.0rc0 → 2.12.0

3 weeks ago
HIGHPyPI

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents: before 1.6.58

3 weeks ago
HIGHPyPI

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents: before 1.6.58

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

praisonaiagents: 1.5.128 → 1.6.58

3 weeks ago
HIGHPyPI

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: before 1.6.58

3 weeks ago
HIGHPyPI

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

praisonai: before 4.6.58

3 weeks ago
CRITICALPyPI

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed: before 5.1.2

3 weeks ago
HIGHPyPI

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

praisonaiagents: before 1.6.58

3 weeks ago
HIGHPyPI

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml-parser: before 3.0.2

3 weeks ago
HIGHPyPI

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

djust: before 1.0.4

3 weeks ago
CRITICALPyPI

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

praisonaiagents: 0.12.12 → 1.6.58

3 weeks ago
UNKNOWNPyPI

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the Transition

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code wit

nltk: before 3.10.0

3 weeks ago
MEDIUMPyPI

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

jupyterhub: before 5.5.0

3 weeks ago
UNKNOWNPyPI

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an

nltk: before 3.10.3

3 weeks ago
HIGHPyPI

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

praisonai: before 4.6.58

3 weeks ago
HIGHPyPI

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

eml-parser: before 3.0.2

3 weeks ago
HIGHPyPI

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

nextcloud-mcp-server: before 0.117.2

3 weeks ago
HIGHPyPI

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

icalendar: 7.1.0 → 7.1.3

3 weeks ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

3 weeks ago
CRITICALPyPI

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway: before 1.0.2

3 weeks ago
UNKNOWNPyPI

Malicious code in multyproccess (PyPI)

Malicious code in multyproccess (PyPI)

3 weeks ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

3 weeks ago
UNKNOWNPyPI

Malicious code in msrcpoc (PyPI)

Malicious code in msrcpoc (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in py-devoli-common (PyPI)

Malicious code in py-devoli-common (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in envprovision (PyPI)

Malicious code in envprovision (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in cryptgraphy (PyPI)

Malicious code in cryptgraphy (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in mlflow-otel-instrumentor (PyPI)

Malicious code in mlflow-otel-instrumentor (PyPI)

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process.

nltk: before 3.9.4

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.

nltk: before 3.9.3

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.

nltk: before 3.9.4

3 weeks ago
UNKNOWNPyPI

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

nltk: before 3.10.0

3 weeks ago
UNKNOWNPyPI

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.

nltk: 3.10.0 → 3.10.2

3 weeks ago
MEDIUMPyPI

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who contro

nltk: 3.9.4 → 3.10.3

3 weeks ago
UNKNOWNPyPI

Malicious code in scrambleeeer (PyPI)

Malicious code in scrambleeeer (PyPI)

3 weeks ago
MEDIUMPyPI

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure

nltk: 3.9.4 → 3.10.3

3 weeks ago
CRITICALPyPI

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

nltk: 3.10.0 → 3.10.3

3 weeks ago
UNKNOWNPyPI

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

nltk: before 3.10.0

3 weeks ago
UNKNOWNPyPI

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebin

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

nltk: before 3.10.0

3 weeks ago
UNKNOWNPyPI

Malicious code in scrambleeer (PyPI)

Malicious code in scrambleeer (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in requests-crypt (PyPI)

Malicious code in requests-crypt (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in boto4 (PyPI)

Malicious code in boto4 (PyPI)

3 weeks ago
CRITICALPyPI

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

xinference: before 2.7.0

3 weeks ago
HIGHPyPI

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

nltk: before 3.10.1

3 weeks ago
CRITICALPyPI

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

hydra-core: before 1.3.4

3 weeks ago
UNKNOWNPyPI

Malicious code in reqcrypts (PyPI)

Malicious code in reqcrypts (PyPI)

3 weeks ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

3 weeks ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

3 weeks ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

wagtail: before 7.0.9

3 weeks ago
HIGHPyPI

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval: before 1.0.9

3 weeks ago
MEDIUMPyPI

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node: before 0.9.0a11

3 weeks ago
HIGHPyPI

Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

wagtail: before 7.0.8

3 weeks ago
HIGHPyPI

Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

wagtail: 7.3 → 7.3.3

3 weeks ago
MODERATEPyPI

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

zoo-kcl: before 0.3.153

3 weeks ago
HIGHPyPI

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

wagtail: before 7.0.9

3 weeks ago
MEDIUMPyPI

Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

wagtail: before 7.0.8

3 weeks ago
MODERATEPyPI

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

zoo-kcl: before 0.3.129

3 weeks ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

wagtail: before 7.0.8

3 weeks ago
MEDIUMPyPI

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

wagtail: before 7.0.9

3 weeks ago
HIGHPyPI

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

wagtail: before 7.0.9

3 weeks ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

3 weeks ago
MEDIUMPyPI

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

wagtail: before 7.0.9

3 weeks ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

3 weeks ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-checkpoint-mongodb: before 0.3.0

3 weeks ago
HIGHPyPI

asteval has a Sandbox Escape via BaseException Subclasses

asteval has a Sandbox Escape via BaseException Subclasses

asteval: before 1.0.9

3 weeks ago
MEDIUMPyPI

Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

wagtail: before 7.0.8

3 weeks ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens-cli: before 1.2.3

3 weeks ago
HIGHPyPI

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: before 0.10.0

3 weeks ago
HIGHPyPI

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: before 0.10.0

3 weeks ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

3 weeks ago
UNKNOWNPyPI

Malicious code in reqcrypt-dev (PyPI)

Malicious code in reqcrypt-dev (PyPI)

3 weeks ago
HIGHExploitedPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: before 3.15.0

3 weeks ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

3 weeks ago
UNKNOWNPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

3 weeks ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

3 weeks ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

3 weeks ago
UNKNOWNPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

3 weeks ago
HIGHPyPI

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

homeassistant: before 2026.6.0

3 weeks ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

3 weeks ago
CRITICALPyPI

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes: before 3.9.0

3 weeks ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

3 weeks ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

3 weeks ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

3 weeks ago
UNKNOWNPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

3 weeks ago
UNKNOWNPyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: all versions

3 weeks ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

3 weeks ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

3 weeks ago
MEDIUMPyPI

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

sglang: all versions

3 weeks ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

3 weeks ago
HIGHPyPI

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

libp2p: all versions

3 weeks ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

3 weeks ago
UNKNOWNPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

3 weeks ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

3 weeks ago
HIGHPyPI

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: before 0.22.0

3 weeks ago
UNKNOWNPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

3 weeks ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

3 weeks ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

3 weeks ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

3 weeks ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

3 weeks ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

3 weeks ago
UNKNOWNPyPI

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

jupyterlab: 3.3.0 → 4.5.10

3 weeks ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

3 weeks ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

3 weeks ago
UNKNOWNPyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

jupyterlab: before 4.5.10

3 weeks ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens: before 1.2.3

3 weeks ago
HIGHPyPI

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

mlflow: 2.14.0rc0 → 3.13.0rc0

3 weeks ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

3 weeks ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai: 1.65.0 → 1.106.0

3 weeks ago
UNKNOWNPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

3 weeks ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

3 weeks ago
UNKNOWNPyPI

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

jupyterlab: 4.5.0 → 4.5.10

3 weeks ago
UNKNOWNPyPI

Malicious code in rc4-secure (PyPI)

Malicious code in rc4-secure (PyPI)

3 weeks ago
CRITICALPyPI

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

document-merge-service: before 9.1.0

3 weeks ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

3 weeks ago
HIGHPyPI

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

geolens: before 1.2.4

3 weeks ago
UNKNOWNPyPI

Malicious code in libasync (PyPI)

Malicious code in libasync (PyPI)

3 weeks ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

3 weeks ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

3 weeks ago
UNKNOWNPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

3 weeks ago
HIGHPyPI

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

copier: 9.5.0 → 9.15.2

3 weeks ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

3 weeks ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

4 weeks ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

4 weeks ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

4 weeks ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

4 weeks ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

4 weeks ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

4 weeks ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

4 weeks ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

4 weeks ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

4 weeks ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

4 weeks ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

4 weeks ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

4 weeks ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

4 weeks ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

4 weeks ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

4 weeks ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

4 weeks ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

4 weeks ago
HIGHPyPI

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

monai: before 1.6.0

4 weeks ago
CRITICALPyPI

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

monai: before 1.6.0

4 weeks ago
UNKNOWNPyPI

Malicious code in deepface-weight (PyPI)

Malicious code in deepface-weight (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in reqcrypt (PyPI)

Malicious code in reqcrypt (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in deepface-weights (PyPI)

Malicious code in deepface-weights (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in httpz-requests (PyPI)

Malicious code in httpz-requests (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in infogram-bot (PyPI)

Malicious code in infogram-bot (PyPI)

4 weeks ago
CRITICALPyPI

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

monai: before 1.6.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed,

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles fr

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugi

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHPyPI

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost.

openssl-encrypt: before 1.4.6

4 weeks ago
HIGHPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation ch

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

4 weeks ago
HIGHPyPI

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hs

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to

openssl-encrypt: before 1.4.7

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Pyth

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementa

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. A

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.

openssl-encrypt: before 1.4.0

4 weeks ago
MODERATEPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

4 weeks ago
HIGHPyPI

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of op

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recover

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHExploitedPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: before 3.15.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared a

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method th

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

4 weeks ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

4 weeks ago
HIGHPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

4 weeks ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

4 weeks ago
HIGHPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHPyPI

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

openssl-encrypt: before 1.4.0

4 weeks ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

4 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silent

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.

openssl-encrypt: before 1.4.0

4 weeks ago
UNKNOWNPyPI

Malicious code in kb-ai (PyPI)

Malicious code in kb-ai (PyPI)

4 weeks ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

4 weeks ago
UNKNOWNPyPI

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.

gitpython: before 3.1.55

4 weeks ago
UNKNOWNPyPI

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing.

gitpython: before 3.1.56

4 weeks ago
UNKNOWNPyPI

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.

gitpython: before 3.1.57

4 weeks ago
CRITICALPyPI

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

gitpython: before 3.1.54

4 weeks ago
UNKNOWNPyPI

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.

gitpython: before 3.1.57

4 weeks ago
UNKNOWNPyPI

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS commands via the --upload-pack parameter.

gitpython: before 3.1.54

4 weeks ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

4 weeks ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

4 weeks ago
HIGHPyPI

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: before 1.1.0

4 weeks ago
HIGHPyPI

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: before 3.10.0

4 weeks ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

4 weeks ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

4 weeks ago
HIGHPyPI

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat

apache-airflow: before 3.3.1

4 weeks ago
MEDIUMPyPI

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m

apache-airflow: before 3.3.1

4 weeks ago
HIGHPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

4 weeks ago
HIGHPyPI

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus

apache-airflow-providers-google: before 22.3.0

4 weeks ago
HIGHPyPI

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore

apache-airflow: before 3.3.1

4 weeks ago
CRITICALPyPI

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce

apache-airflow: 3.3.0 → 3.3.1

4 weeks ago
HIGHPyPI

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

apache-airflow: before 3.3.1

4 weeks ago
MEDIUMPyPI

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds

apache-airflow: 3.3.0 → 3.3.1

4 weeks ago
MEDIUMPyPI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n

apache-airflow: before 3.3.1

4 weeks ago
HIGHPyPI

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se

apache-airflow: before 3.3.1

4 weeks ago
HIGHPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

4 weeks ago
UNKNOWNPyPI

Malicious code in dlmm (PyPI)

Malicious code in dlmm (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in telebot-pro (PyPI)

Malicious code in telebot-pro (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in morpho-sdk (PyPI)

Malicious code in morpho-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in euler-sdk (PyPI)

Malicious code in euler-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in joule-btp-extension (PyPI)

Malicious code in joule-btp-extension (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in joule-sbx-poc (PyPI)

Malicious code in joule-sbx-poc (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in dlmm-sdk (PyPI)

Malicious code in dlmm-sdk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kotoraka (PyPI)

Malicious code in kotoraka (PyPI)

1 month ago
HIGHPyPI

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

Keras model loading is vulnerable to denial of service through HDF5 shape bombs

keras: before 3.15.0

1 month ago
UNKNOWNPyPI

Malicious code in neutrl-core (PyPI)

Malicious code in neutrl-core (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in btcflx (PyPI)

Malicious code in btcflx (PyPI)

1 month ago
HIGHPyPI

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

accelerate: all versions

1 month ago
HIGHPyPI

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe

apache-airflow-providers-yandex: before 4.5.1

1 month ago
HIGHPyPI

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling

apache-airflow-providers-amazon: before 9.34.0

1 month ago
UNKNOWNPyPI

Malicious code in neutrl-contracts (PyPI)

Malicious code in neutrl-contracts (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in bigtime (PyPI)

Malicious code in bigtime (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in chaintest (PyPI)

Malicious code in chaintest (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in pytablute (PyPI)

Malicious code in pytablute (PyPI)

1 month ago
HIGHPyPI

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: before 3.0.7

1 month ago
MEDIUMPyPI

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

open-webui: 0.7.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

open-webui: 0.9.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

open-webui: 0.8.8 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

open-webui: 0.9.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

open-webui: 0.10.0 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

open-webui: 0.5.0 → 0.11.0

1 month ago
MEDIUMPyPI

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

keras: before 3.12.3

1 month ago
HIGHPyPI

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

open-webui: 0.9.6 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

open-webui: 0.6.34 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

open-webui: 0.8.8 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI: DNS Rebinding SSRF Bypass

open-webui: before 0.11.0

1 month ago
HIGHPyPI

Keras: HDF5 links can disclose local file contents

Keras: HDF5 links can disclose local file contents

keras: before 3.12.3

1 month ago
MEDIUMPyPI

Keras: DiskIOStore permits path traversal through crafted layer names

Keras: DiskIOStore permits path traversal through crafted layer names

keras: before 3.12.3

1 month ago
HIGHPyPI

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

open-webui: 0.8.0 → 0.11.0

1 month ago
UNKNOWNPyPI

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: before 6.15.0

1 month ago
HIGHPyPI

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

keras: before 3.12.3

1 month ago
MEDIUMPyPI

h2: Duplicate Host header could facilitate request smuggling

h2: Duplicate Host header could facilitate request smuggling

h2: before 4.4.1

1 month ago
MEDIUMPyPI

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

open-webui: 0.9.6 → 0.11.0

1 month ago
CRITICALPyPI

Keras: Lambda deserialization can bypass safe mode and execute code

Keras: Lambda deserialization can bypass safe mode and execute code

keras: before 3.12.3

1 month ago
HIGHPyPI

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

open-webui: 0.10.0 → 0.11.0

1 month ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: before 6.15.0

1 month ago
HIGHPyPI

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

open-webui: 0.9.6 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

open-webui: 0.9.6 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

open-webui: before 0.11.0

1 month ago
HIGHPyPI

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: before 11.0.1

1 month ago
HIGHPyPI

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

awscli: before 1.45.28

1 month ago
CRITICALPyPI

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

keras: before 3.12.3

1 month ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

open-webui: 0.9.0 → 0.11.0

1 month ago
UNKNOWNPyPI

Malicious code in btcflip (PyPI)

Malicious code in btcflip (PyPI)

1 month ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-sqlite: before 3.1.1

1 month ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-postgres: before 3.1.1

1 month ago
UNKNOWNPyPI

Malicious code in plp-contract (PyPI)

Malicious code in plp-contract (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kotanku (PyPI)

Malicious code in kotanku (PyPI)

1 month ago
MEDIUMPyPI

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared address space (`100.64.0.0/10`). This occurs because Python's `ipaddress` module does not classify such addresses as `is_private` or `is_global`, and the current guard only checks `is_private` and a few explicit categorie

nltk: all versions

1 month ago
UNKNOWNPyPI

Malicious code in cubesat-upstream-driver (PyPI)

Malicious code in cubesat-upstream-driver (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in riakcs (PyPI)

Malicious code in riakcs (PyPI)

1 month ago
MODERATEPyPI

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: before 6.15.0

1 month ago
HIGHPyPI

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active throug

nltk: before 3.10.0

1 month ago
UNKNOWNPyPI

Malicious code in fastapii (PyPI)

Malicious code in fastapii (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in pydanticc (PyPI)

Malicious code in pydanticc (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in flasq (PyPI)

Malicious code in flasq (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in speed-hashes (PyPI)

Malicious code in speed-hashes (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in cdktn-provider-azurerm (PyPI)

Malicious code in cdktn-provider-azurerm (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in atlas-internal (PyPI)

Malicious code in atlas-internal (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in fast-hashes (PyPI)

Malicious code in fast-hashes (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in idnna (PyPI)

Malicious code in idnna (PyPI)

1 month ago
HIGHPyPI

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

gitpython: before 3.1.58

1 month ago
CRITICALPyPI

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

gitpython: before 3.1.58

1 month ago
HIGHPyPI

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: before 11.0.1

1 month ago
CRITICALPyPI

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

gitpython: before 3.1.58

1 month ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: before 6.15.0

1 month ago
HIGHPyPI

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

gitpython: before 3.1.58

1 month ago
CRITICALPyPI

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

gitpython: before 3.1.58

1 month ago
HIGHPyPI

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

gitpython: before 3.1.58

1 month ago
UNKNOWNPyPI

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside 

apache-polaris: before 1.7.0

1 month ago
UNKNOWNPyPI

Malicious code in xayoub-xctxteam (PyPI)

Malicious code in xayoub-xctxteam (PyPI)

1 month ago
HIGHPyPI

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

awscli: before 1.45.28

1 month ago
UNKNOWNPyPI

Malicious code in decapod-common (PyPI)

Malicious code in decapod-common (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in alphalend-layouts (PyPI)

Malicious code in alphalend-layouts (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in alphalend-abi (PyPI)

Malicious code in alphalend-abi (PyPI)

1 month ago
MEDIUMPyPI

h2: Duplicate Host header could facilitate request smuggling

h2: Duplicate Host header could facilitate request smuggling

h2: before 4.4.1

1 month ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-postgres: before 3.1.1

1 month ago
HIGHPyPI

MLflow AI Gateway permits SSRF through an unvalidated api_base

MLflow AI Gateway permits SSRF through an unvalidated api_base

mlflow: ≥ 3.13.0

1 month ago
UNKNOWNPyPI

Malicious code in uncrypt (PyPI)

Malicious code in uncrypt (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in eth-account-wallet (PyPI)

Malicious code in eth-account-wallet (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in mnemonic-py (PyPI)

Malicious code in mnemonic-py (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in numpyp (PyPI)

Malicious code in numpyp (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in gcli-control (PyPI)

Malicious code in gcli-control (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in solana-sniper-bot (PyPI)

Malicious code in solana-sniper-bot (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in defi-sdk-py (PyPI)

Malicious code in defi-sdk-py (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in bitcoinlib-py (PyPI)

Malicious code in bitcoinlib-py (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in crypto-trading-toolkit (PyPI)

Malicious code in crypto-trading-toolkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in bip39-py (PyPI)

Malicious code in bip39-py (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in crypto-wallet-sdk (PyPI)

Malicious code in crypto-wallet-sdk (PyPI)

1 month ago
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

1 month agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

1 month agoEPSS 0%
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

1 month agoEPSS 0%
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

1 month agoEPSS 0%
UNKNOWNPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

1 month agoEPSS 0%
MEDIUMPyPI

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

deepsearcher: all versions

1 month agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: all versions

1 month agoEPSS 0%
UNKNOWNPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

1 month agoEPSS 0%
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

1 month agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

1 month agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

1 month ago
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

1 month agoEPSS 0%
UNKNOWNPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: before 0.15.0

1 month agoEPSS 0%
UNKNOWNPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: before 49.0.0

1 month agoEPSS 0%
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

1 month agoEPSS 0%
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

1 month agoEPSS 0%
MEDIUMPyPI

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

mysql-mcp-server: before 0.3.0

1 month agoEPSS 0%
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in psbt-utils (PyPI)

Malicious code in psbt-utils (PyPI)

1 month ago
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 month ago
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

1 month agoEPSS 0%
UNKNOWNPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: before 49.0.0

1 month agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code in launchdarkly-ai-server-sdk (PyPI)

1 month ago
MEDIUMPyPI

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

nanobot-ai: before 0.2.1

1 month agoEPSS 0%
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

1 month agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

1 month ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

1 month agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

1 month ago
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

1 month ago
UNKNOWNPyPI

Malicious code in coldcard-helpers (PyPI)

Malicious code in coldcard-helpers (PyPI)

1 month ago
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

1 month agoEPSS 0%
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in psbt-helpers (PyPI)

Malicious code in psbt-helpers (PyPI)

1 month ago
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 month ago
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

1 month agoEPSS 0%
UNKNOWNPyPI

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea

django: before 5.2.17

1 month ago
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

1 month agoEPSS 0%
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

open-webui: 0.9.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

1 month ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

open-webui: 0.9.0 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

open-webui: before 0.11.0

1 month ago
UNKNOWNPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI: DNS Rebinding SSRF Bypass

open-webui: before 0.11.0

1 month ago
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

1 month agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

1 month agoEPSS 0%
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

open-webui: 0.6.34 → 0.11.0

1 month ago
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

1 month agoEPSS 0%
HIGHPyPI

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

1 month agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent: all versions

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

open-webui: 0.7.0 → 0.11.0

1 month ago
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

open-webui: 0.9.6 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

open-webui: 0.9.6 → 0.11.0

1 month ago
UNKNOWNPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

1 month agoEPSS 0%
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

open-webui: 0.10.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

open-webui: 0.10.0 → 0.11.0

1 month ago
UNKNOWNPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

open-webui: 0.8.0 → 0.11.0

1 month ago
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

1 month agoEPSS 0%
HIGHPyPI

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

awxkit: all versions

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

open-webui: 0.8.8 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

open-webui: 0.5.0 → 0.11.0

1 month ago
HIGHPyPI

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

open-webui: 0.9.6 → 0.11.0

1 month ago
UNKNOWNPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

open-webui: 0.8.8 → 0.11.0

1 month ago
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

open-webui: 0.9.0 → 0.11.0

1 month ago
MEDIUMPyPI

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

open-webui: 0.9.6 → 0.11.0

1 month ago
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: before 2.26.7

1 month agoEPSS 0%
MODERATEPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

1 month agoEPSS 0%
HIGHPyPI

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

gitpython: before 3.1.57

1 month ago
HIGHPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

1 month agoEPSS 0%
HIGHPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

1 month agoEPSS 0%
HIGHPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: 42.0.0 → 49.0.0

1 month agoEPSS 0%
MODERATEPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

1 month agoEPSS 0%
HIGHPyPI

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

gitpython: before 3.1.57

1 month ago
MODERATEPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: 45.0.0 → 49.0.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in instalogin1234 (PyPI)

Malicious code in instalogin1234 (PyPI)

1 month ago
MEDIUMPyPI

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

gitpython: before 3.1.56

1 month ago
HIGHPyPI

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

transformers: before 5.10.0

1 month ago
UNKNOWNPyPI

Malicious code in trongriden (PyPI)

Malicious code in trongriden (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in wacve-utils (PyPI)

Malicious code in wacve-utils (PyPI)

1 month ago
HIGHPyPI

Keras: HDF5 links can disclose local file contents

Keras: HDF5 links can disclose local file contents

keras: before 3.12.3

1 month ago
UNKNOWNPyPI

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.

gitpython: 3.1.50 → 3.1.51

1 month ago
UNKNOWNPyPI

Malicious code in nvtorch-oot-nightly (PyPI)

Malicious code in nvtorch-oot-nightly (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in trtllm-subdir-test (PyPI)

Malicious code in trtllm-subdir-test (PyPI)

1 month ago
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in catalogai (PyPI)

Malicious code in catalogai (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in telerape (PyPI)

Malicious code in telerape (PyPI)

1 month ago
HIGHPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in asdk-plugin-ai-platform (PyPI)

Malicious code in asdk-plugin-ai-platform (PyPI)

1 month ago
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 month ago
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in aiprepkit (PyPI)

Malicious code in aiprepkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ailaunchkit (PyPI)

Malicious code in ailaunchkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in walmart-genai-trace (PyPI)

Malicious code in walmart-genai-trace (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in reguestsc (PyPI)

Malicious code in reguestsc (PyPI)

1 month ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in aichannel (PyPI)

Malicious code in aichannel (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in cognikit (PyPI)

Malicious code in cognikit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in aiassistcore (PyPI)

Malicious code in aiassistcore (PyPI)

1 month ago
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in asdk-plugin-alphagen (PyPI)

Malicious code in asdk-plugin-alphagen (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in asdk-plugin-legacy (PyPI)

Malicious code in asdk-plugin-legacy (PyPI)

1 month ago
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

1 month agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

1 month ago
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

1 month ago
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

1 month agoEPSS 0%
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

1 month agoEPSS 0%
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

1 month agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

1 month ago
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in ml-data-shared (PyPI)

Malicious code in ml-data-shared (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in mcp-search-server (PyPI)

Malicious code in mcp-search-server (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ml-shared (PyPI)

Malicious code in ml-shared (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in phabricator-client (PyPI)

Malicious code in phabricator-client (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ai-perf-toolkit (PyPI)

Malicious code in ai-perf-toolkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ml-fdbk-shared (PyPI)

Malicious code in ml-fdbk-shared (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ml-nps-shared (PyPI)

Malicious code in ml-nps-shared (PyPI)

1 month ago
MODERATEPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

1 month agoEPSS 0%
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: 2.26.6 → 2.26.7

1 month agoEPSS 0%
HIGHPyPI

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from a

pip: before 26.2

1 month ago
MODERATEPyPI

pip would incorrectly handle doubly-encoded package URLs from indexes

pip would incorrectly handle doubly-encoded package URLs from indexes

pip: before 26.2.0

1 month ago
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

1 month agoEPSS 0%
MODERATEPyPI

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

matrix-commander: all versions

1 month ago
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

1 month agoEPSS 0%
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

1 month agoEPSS 0%
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

1 month agoEPSS 0%
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

1 month agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in vtranalytic (PyPI)

Malicious code in vtranalytic (PyPI)

1 month ago
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

1 month agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

1 month agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

1 month agoEPSS 0%
HIGHPyPI

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

thrift: before 0.24.0

1 month ago
HIGHPyPI

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

thrift: before 0.24.0

1 month ago
HIGHPyPI

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

thrift: before 0.24.0

1 month ago
UNKNOWNPyPI

Malicious code in cfgzen (PyPI)

Malicious code in cfgzen (PyPI)

1 month ago
CRITICALPyPI

NLTK vulnerable to Eval Injection via collocations CLI arguments

NLTK vulnerable to Eval Injection via collocations CLI arguments

nltk: before 3.9.3

1 month ago
UNKNOWNPyPI

Malicious code in blessclient (PyPI)

Malicious code in blessclient (PyPI)

1 month ago
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

gitpython: before 3.1.55

1 month ago
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

httplib2: before 0.32.0

1 month ago
HIGHPyPI

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

gitpython: before 3.1.54

1 month ago
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

1 month ago
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

1 month agoEPSS 0%
UNKNOWNPyPI

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lo

nltk: before 3.9.3

1 month ago
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in discordnv (PyPI)

Malicious code in discordnv (PyPI)

1 month ago
UNKNOWNPyPI

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.

datasets: before 5.0.1

1 month ago
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

gitpython: before 3.1.53

1 month agoEPSS 0%
CRITICALPyPI

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

gitpython: before 3.1.54

1 month ago
CRITICALPyPI

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

gitpython: before 3.1.54

1 month ago
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

1 month agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

1 month ago
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

1 month ago
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

1 month agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

1 month agoEPSS 0%
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

1 month agoEPSS 0%
CRITICALPyPI

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

ray: before 2.56.0

1 month ago
HIGHPyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: all versions

1 month ago
MODERATEPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

1 month agoEPSS 0%
HIGHPyPI

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

libp2p: all versions

1 month ago
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

1 month agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

1 month agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

1 month agoEPSS 0%
MODERATEPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

1 month agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

1 month agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

1 month agoEPSS 0%
MODERATEPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

1 month agoEPSS 0%
LOWPyPI

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

litellm: before 1.82.0

1 month ago
MODERATEPyPI

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

jupyterlab: 4.6.0 → 4.6.2

1 month ago
MODERATEPyPI

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

jupyterlab: 4.6.0 → 4.6.2

1 month ago
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

jupyterlab: 4.6.0 → 4.6.2

1 month ago
UNKNOWNPyPI

Malicious code in make-helper (PyPI)

Malicious code in make-helper (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in dev-helper-bg (PyPI)

Malicious code in dev-helper-bg (PyPI)

1 month ago
MODERATEPyPI

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

LiteLLM: Arbitrary file write via path traversal in Skills archive extraction

litellm: before 1.83.7

1 month ago
LOWPyPI

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

jupyterlab: 4.6.0 → 4.6.2

1 month ago
HIGHPyPI

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback

litellm: before 1.84.0

1 month ago
LOWPyPI

LiteLLM: Local file read via request-supplied OIDC file references

LiteLLM: Local file read via request-supplied OIDC file references

litellm: before 1.83.10

1 month ago
HIGHPyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

jupyterlab: 4.6.0 → 4.6.2

1 month ago
CRITICALPyPI

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

gitpython: before 3.1.51

1 month agoEPSS 1%
HIGHPyPI

pyasn1: Uncontrolled resource consumption when converting decoded REAL values

pyasn1: Uncontrolled resource consumption when converting decoded REAL values

pyasn1: before 0.6.4

1 month ago
HIGHPyPI

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

gitpython: before 3.1.52

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in lebinfmt (PyPI)

Malicious code in lebinfmt (PyPI)

1 month ago
HIGHPyPI

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

capstone: before 5.0.8

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in fluffy-octo-broccoli (PyPI)

Malicious code in fluffy-octo-broccoli (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in rasterkit (PyPI)

Malicious code in rasterkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in colorstack (PyPI)

Malicious code in colorstack (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in comp-colors (PyPI)

Malicious code in comp-colors (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in rasterkit-demo (PyPI)

Malicious code in rasterkit-demo (PyPI)

1 month ago
HIGHPyPI

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

homeassistant: before 2026.6.0

1 month ago
UNKNOWNPyPI

Malicious code in reimagined-broccoli (PyPI)

Malicious code in reimagined-broccoli (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in animated-octo-spoon (PyPI)

Malicious code in animated-octo-spoon (PyPI)

1 month ago
HIGHPyPI

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

gitpython: 3.1.50 → 3.1.51

1 month agoEPSS 0%
HIGHPyPI

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1: before 0.6.4

1 month agoEPSS 0%
HIGHPyPI

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

setuptools: before 83.0.0

1 month ago
HIGHPyPI

pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service

pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service

pyasn1: before 0.6.4

1 month ago
CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

gitpython: before 3.1.51

1 month agoEPSS 1%
HIGHPyPI

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

pillow: 5.1.0 → 12.3.0

1 month ago
HIGHPyPI

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

pillow: before 12.3.0

1 month ago
MEDIUMPyPI

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

pillow: 12.0.0 → 12.3.0

1 month ago
HIGHPyPI

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

pillow: before 12.3.0

1 month ago
HIGHPyPI

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

pillow: before 12.3.0

1 month ago
MEDIUMPyPI

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

pillow: before 12.3.0

1 month ago
HIGHPyPI

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

pillow: before 12.3.0

1 month ago
UNKNOWNPyPI

Malicious code in neroteam-v1 (PyPI)

Malicious code in neroteam-v1 (PyPI)

1 month ago
HIGHPyPI

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

pillow: 5.2.0 → 12.3.0

1 month ago
HIGHPyPI

vLLM denial of service via prompt embeds on M-RoPE models

vLLM denial of service via prompt embeds on M-RoPE models

vllm: 0.12.0 → 0.24.0

1 month ago
UNKNOWNPyPI

Malicious code in paperclip-ai (PyPI)

Malicious code in paperclip-ai (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh2 (PyPI)

Malicious code in hello-world-test-mh2 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh3 (PyPI)

Malicious code in hello-world-test-mh3 (PyPI)

1 month ago
HIGHPyPI

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

pillow: before 12.3.0

1 month ago
UNKNOWNPyPI

Malicious code in shark-e2e-bnsneo (PyPI)

Malicious code in shark-e2e-bnsneo (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in roles-royce (PyPI)

Malicious code in roles-royce (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in trongrider (PyPI)

Malicious code in trongrider (PyPI)

1 month ago
HIGHPyPI

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

pillow: before 12.3.0

1 month ago
UNKNOWNPyPI

Malicious code in kimitalk (PyPI)

Malicious code in kimitalk (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in nemopush (PyPI)

Malicious code in nemopush (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kimichat (PyPI)

Malicious code in kimichat (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ml-core-airflow-auth (PyPI)

Malicious code in ml-core-airflow-auth (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in automatic-octo-invention (PyPI)

Malicious code in automatic-octo-invention (PyPI)

1 month ago
HIGHPyPI

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

pillow: 8.2.0 → 12.3.0

1 month ago
UNKNOWNPyPI

Malicious code in vantrala (PyPI)

Malicious code in vantrala (PyPI)

1 month ago
HIGHPyPI

Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`

Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`

pillow: before 12.3.0

1 month ago
HIGHPyPI

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

pillow: before 12.3.0

1 month ago
UNKNOWNPyPI

Malicious code in data-parser-utils (PyPI)

Malicious code in data-parser-utils (PyPI)

1 month ago
CRITICALPyPI

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

keras: before 3.12.3

1 month ago
UNKNOWNPyPI

Malicious code in python-devplatform-client (PyPI)

Malicious code in python-devplatform-client (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in tinkoff-cloud-apis-internal (PyPI)

Malicious code in tinkoff-cloud-apis-internal (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in mlflow-ui (PyPI)

Malicious code in mlflow-ui (PyPI)

1 month ago
UNKNOWNPyPI

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope.

surrealdb: before 1.0.1

1 month ago
UNKNOWNPyPI

Malicious code in dwh-kafka-client (PyPI)

Malicious code in dwh-kafka-client (PyPI)

2 months ago
HIGHPyPI

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

prompty: before 2.0.0b2

2 months agoEPSS 1%
HIGHPyPI

vLLM has Remote DoS via Invalid Recovered Token Reinjection

vLLM has Remote DoS via Invalid Recovered Token Reinjection

vllm: 0.17.1 → 0.24.0

2 months ago
HIGHPyPI

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

vllm: before 0.24.0

2 months ago
UNKNOWNPyPI

Malicious code in discord-telemetry (PyPI)

Malicious code in discord-telemetry (PyPI)

2 months ago
UNKNOWNPyPI

Malicious code in abseil-py (PyPI)

Malicious code in abseil-py (PyPI)

2 months ago
HIGHPyPI

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

mcp: before 1.28.1

2 months ago
CRITICALPyPI

Snowflake Connector for Python improperly verifies TLS hostnames

Snowflake Connector for Python improperly verifies TLS hostnames

snowflake-connector-python: before 3.18.1

2 months ago
HIGHPyPI

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

mcp: 1.23.0 → 1.27.2

2 months ago
HIGHPyPI

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

mcp: before 1.27.2

2 months ago
UNKNOWNPyPI

Malicious code in xyq-drama-skill (PyPI)

Malicious code in xyq-drama-skill (PyPI)

2 months ago
CRITICALPyPI

PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters

PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters

lightning: before 2022.6.15

2 months ago
HIGHPyPI

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

ddtrace: before 4.8.2

2 months agoEPSS 0%
UNKNOWNPyPI

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.

pytorch-lightning: before 2.6.6

2 months ago
UNKNOWNPyPI

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.

lightning: before 2.6.6

2 months ago
UNKNOWNPyPI

Malicious code in northstart-sdk (PyPI)

Malicious code in northstart-sdk (PyPI)

2 months ago
HIGHPyPI

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools SSRF redirect bypass exposes internal services

crewai-tools: before 1.15.1

2 months ago
HIGHPyPI

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

snowflake-sqlalchemy: 1.1.6 → 1.11.0

2 months ago
MEDIUMPyPI

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

keras: before 3.12.3

2 months ago
MEDIUMPyPI

PyOD persistence.load deserializes untrusted artifacts before validation

PyOD persistence.load deserializes untrusted artifacts before validation

pyod: 3.5.0 → 3.6.2

2 months ago
HIGHPyPI

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

praisonaiagents: before 4.5.128

2 months agoEPSS 0%
CRITICALPyPI

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization

pytorch-lightning: all versions

2 months ago
HIGHPyPI

OpenStack Ironic has an Incorrect Resource Transfer Between Spheres

OpenStack Ironic has an Incorrect Resource Transfer Between Spheres

ironic-python-agent: before 26.1.6

2 months ago
HIGHPyPI

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email instead of binding token issuance to the validated SAML configuration. An authenticated attacker with a controlled SAML IdP could complete a valid SAML flow for an attacker-controlled domain while as

prowler-cloud: before 5.30.3

2 months ago
HIGHPyPI

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: before 0.22.0

2 months ago

Tooling for PyPI

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPackagistPubRubyGemsSwiftURLcrates.ionpm