PyPI incidents
Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in crypto-trading-toolkit (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in bitcoinlib-py (PyPI)
Malicious code in bip39-py (PyPI)
Malicious code in bip39-py (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
Malicious code in crypto-wallet-sdk (PyPI)
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: before 49.0.0
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
open-webui: 0.8.8 → 0.11.0
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
Malicious code in psbt-helpers (PyPI)
Malicious code in psbt-helpers (PyPI)
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
open-webui: 0.9.0 → 0.11.0
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
open-webui: 0.9.0 → 0.11.0
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
open-webui: 0.8.0 → 0.11.0
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
open-webui: 0.9.6 → 0.11.0
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
open-webui: 0.9.0 → 0.11.0
Malicious code in psbt-utils (PyPI)
Malicious code in psbt-utils (PyPI)
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
open-webui: 0.9.6 → 0.11.0
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
open-webui: 0.5.0 → 0.11.0
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
open-webui: 0.10.0 → 0.11.0
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
mysql-mcp-server: before 0.3.0
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
nanobot-ai: before 0.2.1
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: before 49.0.0
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
open-webui: 0.8.8 → 0.11.0
Malicious code in launchdarkly-ai-server-sdk (PyPI)
Malicious code in launchdarkly-ai-server-sdk (PyPI)
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
Open WebUI: DNS Rebinding SSRF Bypass
Open WebUI: DNS Rebinding SSRF Bypass
open-webui: before 0.11.0
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
open-webui: 0.10.0 → 0.11.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
open-webui: before 0.11.0
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent: all versions
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
awxkit: all versions
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
open-webui: 0.7.0 → 0.11.0
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
open-webui: 0.6.34 → 0.11.0
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: before 2.26.7
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
Malicious code in coldcard-helpers (PyPI)
Malicious code in coldcard-helpers (PyPI)
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
open-webui: 0.9.6 → 0.11.0
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
deepsearcher: all versions
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: before 0.15.0
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
open-webui: 0.9.6 → 0.11.0
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: all versions
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
AIOHTTP: HTTP request smuggling via WebSocket upgrade
AIOHTTP: HTTP request smuggling via WebSocket upgrade
aiohttp: before 3.14.2
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
cryptography: before 49.0.0
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
gitpython: before 3.1.57
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
cryptography: 44.0.0 → 50.0.0
Malicious code in instalogin1234 (PyPI)
Malicious code in instalogin1234 (PyPI)
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
gitpython: before 3.1.57
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
gitpython: before 3.1.56
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
aiohttp: before 3.14.2
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
cryptography: before 49.0.0
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
aiohttp: before 3.14.3
Malicious code in wacve-utils (PyPI)
Malicious code in wacve-utils (PyPI)
Malicious code in trongriden (PyPI)
Malicious code in trongriden (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
thumbor: before 7.8.0
Malicious code in telerape (PyPI)
Malicious code in telerape (PyPI)
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
nltk: before 3.10.0
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
onionshare-cli: before 2.6.4
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
thumbor: before 7.8.0
OnionShare Receive mode writes uploaded files even when file uploads are disabled
OnionShare Receive mode writes uploaded files even when file uploads are disabled
onionshare-cli: before 2.6.4
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
gemini-bridge: 1.0.0 → 1.3.1
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
thumbor: before 7.8.0
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
thumbor: before 7.8.0
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
nltk: before 3.10.0
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
thumbor: before 7.8.0
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
thumbor: before 7.8.0
Malicious code in aiprepkit (PyPI)
Malicious code in aiprepkit (PyPI)
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
nltk: before 3.10.0
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
Malicious code in catalogai (PyPI)
Malicious code in catalogai (PyPI)
Malicious code in aiassistcore (PyPI)
Malicious code in aiassistcore (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in cognikit (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in ailaunchkit (PyPI)
Malicious code in aichannel (PyPI)
Malicious code in aichannel (PyPI)
Malicious code in reguestsc (PyPI)
Malicious code in reguestsc (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in walmart-genai-trace (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
flyto-core: before 2.26.7
Malicious code in ml-shared (PyPI)
Malicious code in ml-shared (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
Malicious code in ml-fdbk-shared (PyPI)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
flyto-core: before 2.26.7
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
linuxfabrik-lib: before 6.0.0
Malicious code in mcp-search-server (PyPI)
Malicious code in mcp-search-server (PyPI)
Malicious code in ml-nps-shared (PyPI)
Malicious code in ml-nps-shared (PyPI)
Malicious code in phabricator-client (PyPI)
Malicious code in phabricator-client (PyPI)
Malicious code in ml-data-shared (PyPI)
Malicious code in ml-data-shared (PyPI)
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
flyto-core: before 2.26.7
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
flyto-core: before 2.26.7
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
flyto-core: before 2.26.7
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
flyto-core: before 2.26.7
Malicious code in ai-perf-toolkit (PyPI)
Malicious code in ai-perf-toolkit (PyPI)
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
proot-distro: before 5.1.5
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
matrix-commander: all versions
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro: before 5.1.6
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
penelope-shell-handler: before 0.20.0
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi: 2.0.0 → 2.2.1
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
datamodel-code-generator: before 0.63.0
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
datamodel-code-generator: before 0.63.0
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
datamodel-code-generator: 0.14.1 → 0.60.2
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
datamodel-code-generator: 0.52.1 → 0.60.2
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
datamodel-code-generator: 0.9.1 → 0.61.0
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
datamodel-code-generator: 0.9.1 → 0.61.0
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
datamodel-code-generator: before 0.62.0
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
datamodel-code-generator: 0.51.0 → 0.60.2
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
datamodel-code-generator: 0.59.0 → 0.62.0
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
datamodel-code-generator: 0.17.0 → 0.60.2
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
datamodel-code-generator: 0.25.0 → 0.60.1
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
datamodel-code-generator: 0.11.6 → 0.64.0
Malicious code in cfgzen (PyPI)
Malicious code in cfgzen (PyPI)
Malicious code in blessclient (PyPI)
Malicious code in blessclient (PyPI)
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
open-webui: 0.9.0 → 0.10.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
open-webui: 0.8.12 → 0.10.0
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
pymdown-extensions: before 11.0.0
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
open-webui: 0.6.27 → 0.10.0
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
open-webui: before 0.10.0
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
open-webui: before 0.10.0
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
open-webui: before 0.10.0
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
open-webui: before 0.10.0
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
open-webui: 0.9.2 → 0.10.0
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
open-webui: before 0.10.0
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
open-webui: 0.9.6 → 0.10.0
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
bedrock-agentcore: before 1.18.1
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
open-webui: 0.7.0 → 0.10.0
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: before 2026.7.4
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
onnx: 1.3.0 → 1.22.0
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
open-webui: 0.9.5 → 0.10.0
Malicious code in discordnv (PyPI)
Malicious code in discordnv (PyPI)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
gitpython: before 3.1.53
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
open-webui: before 0.10.0
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui: 0.9.6 → 0.10.0
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
open-webui: 0.6.16 → 0.10.0
Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
open-webui: before 0.10.0
AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
awscli: before 1.44.78
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
open-webui: 0.9.0 → 0.10.0
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
open-webui: 0.8.11 → 0.10.0
pypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
pypdf: before 6.14.1
pypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
pypdf: before 6.14.0
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: before 6.14.2
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: before 6.14.0
Malicious code in dev-helper-bg (PyPI)
Malicious code in dev-helper-bg (PyPI)
Malicious code in make-helper (PyPI)
Malicious code in make-helper (PyPI)
Malicious code in rasterkit (PyPI)
Malicious code in rasterkit (PyPI)
GitPython unsafe clone option gate bypass through joined short options
GitPython unsafe clone option gate bypass through joined short options
gitpython: 3.1.50 → 3.1.51
Malicious code in animated-octo-spoon (PyPI)
Malicious code in animated-octo-spoon (PyPI)
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.
capstone: before 5.0.8
Malicious code in reimagined-broccoli (PyPI)
Malicious code in reimagined-broccoli (PyPI)
Malicious code in rasterkit-demo (PyPI)
Malicious code in rasterkit-demo (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in colorstack (PyPI)
Malicious code in comp-colors (PyPI)
Malicious code in comp-colors (PyPI)
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython: before 3.1.52
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1: before 0.6.4
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython: before 3.1.51
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython: before 3.1.51
Malicious code in fluffy-octo-broccoli (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
Malicious code in vantrala (PyPI)
Malicious code in vantrala (PyPI)
Malicious code in nemopush (PyPI)
Malicious code in nemopush (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Malicious code in automatic-octo-invention (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in kimichat (PyPI)
Malicious code in kimitalk (PyPI)
Malicious code in kimitalk (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in roles-royce (PyPI)
Malicious code in trongrider (PyPI)
Malicious code in trongrider (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
Malicious code in neroteam-v1 (PyPI)
Malicious code in neroteam-v1 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
Malicious code in data-parser-utils (PyPI)
Malicious code in data-parser-utils (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in tinkoff-cloud-apis-internal (PyPI)
Malicious code in python-devplatform-client (PyPI)
Malicious code in python-devplatform-client (PyPI)
Malicious code in dwh-kafka-client (PyPI)
Malicious code in dwh-kafka-client (PyPI)
Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
prompty: before 2.0.0b2
Malicious code in abseil-py (PyPI)
Malicious code in abseil-py (PyPI)
Malicious code in northstart-sdk (PyPI)
Malicious code in northstart-sdk (PyPI)
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
ddtrace: before 4.8.2
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
praisonaiagents: before 4.5.128
Pulp incorrectly assigns RBAC permissions in tasks that create objects
Pulp incorrectly assigns RBAC permissions in tasks that create objects
pulpcore: all versions
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
aiosmtplib: before 5.1.1
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
jupyterlab: before 4.5.9
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
ouroboros-ai: before 0.42.1
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
pyjwt: 2.0.0 → 2.13.0
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
pyjwt: 2.0.0 → 2.13.0
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-sam
apache-airflow-providers-samba: before 4.12.6
Apache Airflow has a Path Traversal issue
Apache Airflow has a Path Traversal issue
apache-airflow-providers-samba: before 4.12.6
awxkit has a path traversal vulnerability
awxkit has a path traversal vulnerability
awxkit: all versions
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler
mysql-mcp-server: before 0.3.0
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
zilliztech deep-searcher has an Incorrect Privilege Assignment issue
deepsearcher: all versions
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake
oslo-messaging: ≥ 1.0.0
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent: all versions
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: all versions
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
nanobot-ai: before 0.2.1
hermes-agent has an Injection issue
hermes-agent has an Injection issue
hermes-agent: before 0.15.0
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
gitpython: before 3.1.50
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
jupyter-server: before 2.18.0
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
jupyter-server: before 2.18.0
MONAI: Unsafe functions lead to pickle deserialization rce
MONAI: Unsafe functions lead to pickle deserialization rce
monai: before 1.6.0
Black: Arbitrary file writes from unsanitized user input in cache file name
Black: Arbitrary file writes from unsanitized user input in cache file name
black: 24.3.0 → 26.3.1
num2words subjected to phishing attack, two versions published containing malware
num2words subjected to phishing attack, two versions published containing malware
num2words: ≥ 0.5.15
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.
dagster-ge: all versions
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
airflow-diagrams: all versions
Tooling for PyPI
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.