PyPI incidents

Recent PyPI vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

UNKNOWNPyPI

Malicious code in multyproccess (PyPI)

Malicious code in multyproccess (PyPI)

1 day ago
UNKNOWNPyPI

Malicious code in msrcpoc (PyPI)

Malicious code in msrcpoc (PyPI)

1 day ago
CRITICALPyPI

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

mcp-contextforge-gateway: before 1.0.2

1 day ago
HIGHPyPI

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

django-cms: before 5.0.8

1 day ago
MEDIUMPyPI

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

django-cms: before 5.0.8

1 day ago
UNKNOWNPyPI

Malicious code in envprovision (PyPI)

Malicious code in envprovision (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in cryptgraphy (PyPI)

Malicious code in cryptgraphy (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in mlflow-otel-instrumentor (PyPI)

Malicious code in mlflow-otel-instrumentor (PyPI)

2 days ago
UNKNOWNPyPI

Malicious code in scrambleeeer (PyPI)

Malicious code in scrambleeeer (PyPI)

3 days ago
UNKNOWNPyPI

Malicious code in requests-crypt (PyPI)

Malicious code in requests-crypt (PyPI)

4 days ago
CRITICALPyPI

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

xinference: before 2.7.0

4 days ago
UNKNOWNPyPI

Malicious code in boto4 (PyPI)

Malicious code in boto4 (PyPI)

4 days ago
UNKNOWNPyPI

Malicious code in reqcrypts (PyPI)

Malicious code in reqcrypts (PyPI)

4 days ago
CRITICALPyPI

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

hydra-core: before 1.3.4

4 days ago
UNKNOWNPyPI

Malicious code in scrambleeer (PyPI)

Malicious code in scrambleeer (PyPI)

4 days ago
HIGHPyPI

asteval has a Sandbox Escape via BaseException Subclasses

asteval has a Sandbox Escape via BaseException Subclasses

asteval: before 1.0.9

5 days ago
MEDIUMPyPI

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

wagtail: before 7.0.9

5 days ago
HIGHPyPI

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

langgraph-checkpoint-mongodb: before 0.3.0

5 days ago
MEDIUMPyPI

Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

wagtail: before 7.0.8

5 days ago
HIGHPyPI

Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

wagtail: before 7.0.8

5 days ago
HIGHPyPI

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

django-cms: before 5.0.9

5 days ago
MEDIUMPyPI

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django-cms: before 5.0.9

5 days ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

wagtail: before 7.0.9

5 days ago
MEDIUMPyPI

django CMS: Stored XSS in edit-mode plugin exception rendering

django CMS: Stored XSS in edit-mode plugin exception rendering

django-cms: 5.0.8 → 5.0.9

5 days ago
MEDIUMPyPI

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

wagtail: before 7.0.8

5 days ago
MODERATEPyPI

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

zoo-kcl: before 0.3.129

5 days ago
MEDIUMPyPI

Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

wagtail: before 7.0.8

5 days ago
HIGHPyPI

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

django-cms: before 5.0.8

5 days ago
MEDIUMPyPI

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node: before 0.9.0a11

5 days ago
MODERATEPyPI

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

zoo-kcl: before 0.3.153

5 days ago
HIGHPyPI

Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

wagtail: 7.3 → 7.3.3

5 days ago
HIGHPyPI

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval: before 1.0.9

5 days ago
HIGHPyPI

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

wagtail: before 7.0.9

5 days ago
MEDIUMPyPI

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

wagtail: before 7.0.9

5 days ago
HIGHPyPI

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

wagtail: before 7.0.9

5 days ago
HIGHPyPI

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django-cms: before 5.0.8

5 days ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

6 days ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

6 days ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

6 days ago
UNKNOWNPyPI

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

jupyterlab: 3.3.0 → 4.5.10

6 days ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

6 days ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

6 days ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

6 days ago
UNKNOWNPyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

jupyterlab: before 4.5.10

6 days ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens: before 1.2.3

6 days ago
HIGHPyPI

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

mlflow: 2.14.0rc0 → 3.13.0rc0

6 days ago
HIGHExploitedPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: before 3.15.0

6 days ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

6 days ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai: 1.65.0 → 1.106.0

6 days ago
UNKNOWNPyPI

Malicious code in rc4-secure (PyPI)

Malicious code in rc4-secure (PyPI)

6 days ago
CRITICALPyPI

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

document-merge-service: before 9.1.0

6 days ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

6 days ago
HIGHPyPI

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

geolens: before 1.2.4

6 days ago
UNKNOWNPyPI

Malicious code in libasync (PyPI)

Malicious code in libasync (PyPI)

6 days ago
HIGHPyPI

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

langgraph-api: before 0.10.0

6 days ago
HIGHPyPI

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

copier: 9.5.0 → 9.15.2

6 days ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

6 days ago
HIGHPyPI

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

langgraph-api: before 0.10.0

6 days ago
UNKNOWNPyPI

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

jupyterlab: 4.5.0 → 4.5.10

6 days ago
UNKNOWNPyPI

Malicious code in reqcrypt-dev (PyPI)

Malicious code in reqcrypt-dev (PyPI)

6 days ago
UNKNOWNPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

6 days ago
UNKNOWNPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

6 days ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

6 days ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

6 days ago
UNKNOWNPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

6 days ago
HIGHPyPI

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

homeassistant: before 2026.6.0

6 days ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

6 days ago
CRITICALPyPI

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes: before 3.9.0

6 days ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

6 days ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

6 days ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

6 days ago
HIGHPyPI

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: before 0.22.0

6 days ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

6 days ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

6 days ago
UNKNOWNPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

6 days ago
UNKNOWNPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

6 days ago
UNKNOWNPyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: all versions

6 days ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

6 days ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

6 days ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

6 days ago
MEDIUMPyPI

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

sglang: all versions

6 days ago
UNKNOWNPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

6 days ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

6 days ago
HIGHPyPI

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

libp2p: all versions

6 days ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

6 days ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

6 days ago
HIGHPyPI

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data

geolens-cli: before 1.2.3

6 days ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

6 days ago
UNKNOWNPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

6 days ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

6 days ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

6 days ago
HIGHPyPI

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads

mobsf: before 4.5.1

1 week ago
HIGHPyPI

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

monai: before 1.6.0

1 week ago
UNKNOWNPyPI

Malicious code in reqcrypt (PyPI)

Malicious code in reqcrypt (PyPI)

1 week ago
MEDIUMPyPI

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False

lemur: before 1.9.3

1 week ago
UNKNOWNPyPI

Malicious code in deepface-weights (PyPI)

Malicious code in deepface-weights (PyPI)

1 week ago
CRITICALPyPI

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files

monai: before 1.6.0

1 week ago
CRITICALPyPI

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read

resdata: before 6.2.9

1 week ago
MEDIUMPyPI

Copyparty vulnerable to file/dirkey confusion

Copyparty vulnerable to file/dirkey confusion

copyparty: before 1.20.17

1 week ago
HIGHPyPI

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it

lemur: before 1.9.3

1 week ago
CRITICALPyPI

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

monai: before 1.6.0

1 week ago
HIGHPyPI

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

lemur: before 1.9.3

1 week ago
UNKNOWNPyPI

Malicious code in deepface-weight (PyPI)

Malicious code in deepface-weight (PyPI)

1 week ago
MEDIUMPyPI

devpi-server may leak database contents

devpi-server may leak database contents

devpi-server: before 6.20.2

1 week ago
MEDIUMPyPI

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

lemur: before 1.9.3

1 week ago
MEDIUMPyPI

MobSF has SSRF port restriction bypass in assetlinks_check

MobSF has SSRF port restriction bypass in assetlinks_check

mobsf: before 4.5.1

1 week ago
HIGHPyPI

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)

linuxfabrik-lib: before 6.1.0

1 week ago
HIGHPyPI

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority

lemur: before 1.9.3

1 week ago
HIGHPyPI

MobSF's CSRF checks not enforced after Django migration

MobSF's CSRF checks not enforced after Django migration

mobsf: before 4.5.1

1 week ago
HIGHPyPI

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates

lemur: 0.5.0 → 1.9.3

1 week ago
HIGHPyPI

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction

mobsf: before 4.5.1

1 week ago
MEDIUMPyPI

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)

lemur: before 1.9.3

1 week ago
UNKNOWNPyPI

Malicious code in httpz-requests (PyPI)

Malicious code in httpz-requests (PyPI)

1 week ago
HIGHPyPI

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API

lemur: before 1.9.3

1 week ago
CRITICALPyPI

surfio has an out-of-bounds read

surfio has an out-of-bounds read

surfio: before 0.0.19

1 week ago
UNKNOWNPyPI

Malicious code in infogram-bot (PyPI)

Malicious code in infogram-bot (PyPI)

1 week ago
HIGHPyPI

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

Glances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)

glances: before 4.5.6

1 week ago
MODERATEPyPI

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes

sqlparse: before 0.6.0

1 week ago
MEDIUMPyPI

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config

glances: before 4.5.6

1 week ago
HIGHPyPI

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: Quadratic O(n²) DoS in group_comments

sqlparse: before 0.6.0

1 week ago
CRITICALPyPI

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection

glances: 4.5.2 → 4.5.6

1 week ago
HIGHPyPI

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard

glances: before 4.5.6

1 week ago
HIGHPyPI

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction

glances: before 4.5.6

1 week ago
HIGHPyPI

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger

sqlparse: before 0.6.0

1 week ago
HIGHPyPI

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)

sqlparse: before 0.6.0

1 week ago
HIGHExploitedPyPI

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: before 3.15.0

1 week ago
UNKNOWNPyPI

Malicious code in kb-ai (PyPI)

Malicious code in kb-ai (PyPI)

1 week ago
HIGHPyPI

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

mcp-contextforge-gateway: before 1.0.3

1 week ago
HIGHPyPI

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: before 1.1.0

1 week ago
HIGHPyPI

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences

nltk: before 3.10.0

1 week ago
HIGHPyPI

vLLM: Completion prompt lists fan out into unbounded engine requests

vLLM: Completion prompt lists fan out into unbounded engine requests

vllm: 0.19.0 → 0.26.0

1 week ago
HIGHPyPI

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

pydantic-ai-slim: 1.65.0 → 1.106.0

1 week ago
HIGHPyPI

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)

ansible-jailexec: before 2.0.0

1 week ago
HIGHPyPI

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configurat

apache-airflow: before 3.3.1

1 week ago
CRITICALPyPI

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

stata-mcp: before 1.19.0

1 week ago
HIGHPyPI

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those se

apache-airflow: before 3.3.1

1 week ago
MEDIUMPyPI

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: Stored XSS in the HTML export via unescaped dataset title

tablib: before 3.10.0

1 week ago
HIGHPyPI

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

compliance-trestle: before 4.1.0

1 week ago
MEDIUMPyPI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does n

apache-airflow: before 3.3.1

1 week ago
MEDIUMPyPI

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds

apache-airflow: 3.3.0 → 3.3.1

1 week ago
HIGHPyPI

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

apache-airflow: before 3.3.1

1 week ago
CRITICALPyPI

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler proce

apache-airflow: 3.3.0 → 3.3.1

1 week ago
HIGHPyPI

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore

apache-airflow: before 3.3.1

1 week ago
HIGHPyPI

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unus

apache-airflow-providers-google: before 22.3.0

1 week ago
MEDIUMPyPI

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m

apache-airflow: before 3.3.1

1 week ago
UNKNOWNPyPI

Malicious code in morpho-sdk (PyPI)

Malicious code in morpho-sdk (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in dlmm-sdk (PyPI)

Malicious code in dlmm-sdk (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in euler-sdk (PyPI)

Malicious code in euler-sdk (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in joule-btp-extension (PyPI)

Malicious code in joule-btp-extension (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in dlmm (PyPI)

Malicious code in dlmm (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in joule-sbx-poc (PyPI)

Malicious code in joule-sbx-poc (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in telebot-pro (PyPI)

Malicious code in telebot-pro (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in btcflip (PyPI)

Malicious code in btcflip (PyPI)

2 weeks ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

open-webui: 0.9.0 → 0.11.0

2 weeks ago
CRITICALPyPI

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

keras: before 3.12.3

2 weeks ago
HIGHPyPI

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

awscli: before 1.45.28

2 weeks ago
HIGHPyPI

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: before 11.0.1

2 weeks ago
HIGHPyPI

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

open-webui: before 0.11.0

2 weeks ago
MEDIUMPyPI

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

open-webui: 0.9.6 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

open-webui: 0.9.6 → 0.11.0

2 weeks ago
UNKNOWNPyPI

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: before 6.15.0

2 weeks ago
HIGHPyPI

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

open-webui: 0.10.0 → 0.11.0

2 weeks ago
CRITICALPyPI

Keras: Lambda deserialization can bypass safe mode and execute code

Keras: Lambda deserialization can bypass safe mode and execute code

keras: before 3.12.3

2 weeks ago
MEDIUMPyPI

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

open-webui: 0.9.6 → 0.11.0

2 weeks ago
MEDIUMPyPI

h2: Duplicate Host header could facilitate request smuggling

h2: Duplicate Host header could facilitate request smuggling

h2: before 4.4.1

2 weeks ago
HIGHPyPI

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

keras: before 3.12.3

2 weeks ago
UNKNOWNPyPI

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: before 6.15.0

2 weeks ago
HIGHPyPI

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

open-webui: 0.8.0 → 0.11.0

2 weeks ago
MEDIUMPyPI

Keras: DiskIOStore permits path traversal through crafted layer names

Keras: DiskIOStore permits path traversal through crafted layer names

keras: before 3.12.3

2 weeks ago
HIGHPyPI

Keras: HDF5 links can disclose local file contents

Keras: HDF5 links can disclose local file contents

keras: before 3.12.3

2 weeks ago
HIGHPyPI

Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI: DNS Rebinding SSRF Bypass

open-webui: before 0.11.0

2 weeks ago
MEDIUMPyPI

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

open-webui: 0.8.8 → 0.11.0

2 weeks ago
MEDIUMPyPI

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

open-webui: 0.6.34 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

open-webui: 0.9.6 → 0.11.0

2 weeks ago
MEDIUMPyPI

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

keras: before 3.12.3

2 weeks ago
MEDIUMPyPI

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

open-webui: 0.5.0 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

open-webui: 0.10.0 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

open-webui: 0.9.0 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

open-webui: 0.8.8 → 0.11.0

2 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

open-webui: 0.9.0 → 0.11.0

2 weeks ago
MEDIUMPyPI

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

open-webui: 0.7.0 → 0.11.0

2 weeks ago
HIGHPyPI

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: before 3.0.7

2 weeks ago
UNKNOWNPyPI

Malicious code in pytablute (PyPI)

Malicious code in pytablute (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in chaintest (PyPI)

Malicious code in chaintest (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in bigtime (PyPI)

Malicious code in bigtime (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in neutrl-contracts (PyPI)

Malicious code in neutrl-contracts (PyPI)

2 weeks ago
HIGHPyPI

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backe

apache-airflow-providers-yandex: before 4.5.1

2 weeks ago
UNKNOWNPyPI

Malicious code in btcflx (PyPI)

Malicious code in btcflx (PyPI)

2 weeks ago
HIGHPyPI

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling

apache-airflow-providers-amazon: before 9.34.0

2 weeks ago
UNKNOWNPyPI

Malicious code in neutrl-core (PyPI)

Malicious code in neutrl-core (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in kotoraka (PyPI)

Malicious code in kotoraka (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in plp-contract (PyPI)

Malicious code in plp-contract (PyPI)

2 weeks ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-postgres: before 3.1.1

2 weeks ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-sqlite: before 3.1.1

2 weeks ago
UNKNOWNPyPI

Malicious code in cubesat-upstream-driver (PyPI)

Malicious code in cubesat-upstream-driver (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in kotanku (PyPI)

Malicious code in kotanku (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in riakcs (PyPI)

Malicious code in riakcs (PyPI)

2 weeks ago
HIGHPyPI

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

gitpython: before 3.1.58

2 weeks ago
CRITICALPyPI

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

gitpython: before 3.1.58

2 weeks ago
UNKNOWNPyPI

Malicious code in pydanticc (PyPI)

Malicious code in pydanticc (PyPI)

2 weeks ago
CRITICALPyPI

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

gitpython: before 3.1.58

2 weeks ago
UNKNOWNPyPI

Malicious code in speed-hashes (PyPI)

Malicious code in speed-hashes (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in flasq (PyPI)

Malicious code in flasq (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in fast-hashes (PyPI)

Malicious code in fast-hashes (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in atlas-internal (PyPI)

Malicious code in atlas-internal (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in cdktn-provider-azurerm (PyPI)

Malicious code in cdktn-provider-azurerm (PyPI)

2 weeks ago
CRITICALPyPI

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

gitpython: before 3.1.58

2 weeks ago
MODERATEPyPI

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: Possible large memory usage for large /ToUnicode streams

pypdf: before 6.15.0

2 weeks ago
HIGHPyPI

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

gitpython: before 3.1.58

2 weeks ago
HIGHPyPI

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

gitpython: before 3.1.58

2 weeks ago
MODERATEPyPI

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: Possible long runtimes/large memory usage for large CID font width ranges

pypdf: before 6.15.0

2 weeks ago
UNKNOWNPyPI

Malicious code in fastapii (PyPI)

Malicious code in fastapii (PyPI)

2 weeks ago
HIGHPyPI

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors

pymdown-extensions: before 11.0.1

2 weeks ago
UNKNOWNPyPI

Malicious code in idnna (PyPI)

Malicious code in idnna (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in alphalend-layouts (PyPI)

Malicious code in alphalend-layouts (PyPI)

2 weeks ago
UNKNOWNPyPI

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside 

apache-polaris: before 1.7.0

2 weeks ago
UNKNOWNPyPI

Malicious code in decapod-common (PyPI)

Malicious code in decapod-common (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in alphalend-abi (PyPI)

Malicious code in alphalend-abi (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in xayoub-xctxteam (PyPI)

Malicious code in xayoub-xctxteam (PyPI)

2 weeks ago
HIGHPyPI

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

awscli: before 1.45.28

2 weeks ago
MEDIUMPyPI

h2: Duplicate Host header could facilitate request smuggling

h2: Duplicate Host header could facilitate request smuggling

h2: before 4.4.1

2 weeks ago
HIGHPyPI

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores

langgraph-checkpoint-postgres: before 3.1.1

2 weeks ago
UNKNOWNPyPI

Malicious code in crypto-trading-toolkit (PyPI)

Malicious code in crypto-trading-toolkit (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in numpyp (PyPI)

Malicious code in numpyp (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in crypto-wallet-sdk (PyPI)

Malicious code in crypto-wallet-sdk (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in mnemonic-py (PyPI)

Malicious code in mnemonic-py (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in eth-account-wallet (PyPI)

Malicious code in eth-account-wallet (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in uncrypt (PyPI)

Malicious code in uncrypt (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in defi-sdk-py (PyPI)

Malicious code in defi-sdk-py (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in solana-sniper-bot (PyPI)

Malicious code in solana-sniper-bot (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in gcli-control (PyPI)

Malicious code in gcli-control (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in bitcoinlib-py (PyPI)

Malicious code in bitcoinlib-py (PyPI)

2 weeks ago
UNKNOWNPyPI

Malicious code in bip39-py (PyPI)

Malicious code in bip39-py (PyPI)

2 weeks ago
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

3 weeks agoEPSS 0%
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

3 weeks agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

3 weeks agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

3 weeks agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

3 weeks ago
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

3 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

3 weeks agoEPSS 0%
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

3 weeks agoEPSS 0%
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

3 weeks ago
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

3 weeks agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

3 weeks ago
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

nanobot-ai: before 0.2.1

3 weeks agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: before 49.0.0

3 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

3 weeks agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

3 weeks agoEPSS 0%
MEDIUMPyPI

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

mysql-mcp-server: before 0.3.0

3 weeks agoEPSS 0%
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: before 49.0.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

3 weeks agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

3 weeks ago
UNKNOWNPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

3 weeks agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: all versions

3 weeks agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: before 0.15.0

3 weeks agoEPSS 0%
MEDIUMPyPI

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

deepsearcher: all versions

3 weeks agoEPSS 0%
UNKNOWNPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

3 weeks agoEPSS 0%
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

3 weeks agoEPSS 0%
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

3 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

3 weeks agoEPSS 0%
UNKNOWNPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

3 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

3 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

3 weeks agoEPSS 0%
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

3 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

3 weeks agoEPSS 0%
HIGHPyPI

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

awxkit: all versions

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

3 weeks agoEPSS 0%
UNKNOWNPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

3 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

3 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

3 weeks agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent: all versions

3 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

3 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in psbt-helpers (PyPI)

Malicious code in psbt-helpers (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in coldcard-helpers (PyPI)

Malicious code in coldcard-helpers (PyPI)

3 weeks ago
MEDIUMPyPI

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint

open-webui: 0.9.6 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs

open-webui: 0.9.0 → 0.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check

open-webui: 0.8.8 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

open-webui: 0.9.6 → 0.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

open-webui: 0.5.0 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

open-webui: 0.8.8 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client

open-webui: 0.8.0 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

open-webui: 0.10.0 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

open-webui: 0.10.0 → 0.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

open-webui: 0.9.6 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically

open-webui: 0.9.6 → 0.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

Open WebUI: Users denied the image-generation permission can still generate images via chat completions

open-webui: 0.7.0 → 0.11.0

3 weeks ago
MEDIUMPyPI

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering

open-webui: 0.6.34 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI: DNS Rebinding SSRF Bypass

open-webui: before 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

open-webui: before 0.11.0

3 weeks ago
UNKNOWNPyPI

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code in launchdarkly-ai-server-sdk (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in psbt-utils (PyPI)

Malicious code in psbt-utils (PyPI)

3 weeks ago
HIGHPyPI

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

open-webui: 0.9.0 → 0.11.0

3 weeks ago
HIGHPyPI

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing

open-webui: 0.9.0 → 0.11.0

3 weeks ago
UNKNOWNPyPI

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected. Ea

django: before 5.2.17

3 weeks ago
HIGHPyPI

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

aiohttp: before 3.14.3

3 weeks agoEPSS 0%
MEDIUMPyPI

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

gitpython: before 3.1.56

3 weeks ago
HIGHPyPI

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography: 44.0.0 → 50.0.0

3 weeks agoEPSS 0%
MODERATEPyPI

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

aiohttp: before 3.14.2

3 weeks agoEPSS 0%
MODERATEPyPI

AIOHTTP: HTTP request smuggling via WebSocket upgrade

AIOHTTP: HTTP request smuggling via WebSocket upgrade

aiohttp: before 3.14.2

3 weeks agoEPSS 0%
MODERATEPyPI

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees

cryptography: before 49.0.0

3 weeks agoEPSS 0%
HIGHPyPI

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

gitpython: before 3.1.57

3 weeks ago
HIGHPyPI

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

gitpython: before 3.1.57

3 weeks ago
UNKNOWNPyPI

Malicious code in instalogin1234 (PyPI)

Malicious code in instalogin1234 (PyPI)

3 weeks ago
HIGHPyPI

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

cryptography: before 49.0.0

3 weeks agoEPSS 0%
HIGHPyPI

Keras: HDF5 links can disclose local file contents

Keras: HDF5 links can disclose local file contents

keras: before 3.12.3

3 weeks ago
UNKNOWNPyPI

Malicious code in trongriden (PyPI)

Malicious code in trongriden (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in wacve-utils (PyPI)

Malicious code in wacve-utils (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in nvtorch-oot-nightly (PyPI)

Malicious code in nvtorch-oot-nightly (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in trtllm-subdir-test (PyPI)

Malicious code in trtllm-subdir-test (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in asdk-plugin-ai-platform (PyPI)

Malicious code in asdk-plugin-ai-platform (PyPI)

3 weeks ago
HIGHPyPI

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

3 weeks ago
UNKNOWNPyPI

Malicious code in telerape (PyPI)

Malicious code in telerape (PyPI)

3 weeks ago
HIGHPyPI

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

onionshare-cli: before 2.6.4

3 weeks agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS

thumbor: before 7.8.0

3 weeks agoEPSS 0%
MEDIUMPyPI

OnionShare Receive mode writes uploaded files even when file uploads are disabled

OnionShare Receive mode writes uploaded files even when file uploads are disabled

onionshare-cli: before 2.6.4

3 weeks agoEPSS 0%
HIGHPyPI

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

nltk: before 3.10.0

3 weeks ago
HIGHPyPI

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS

thumbor: before 7.8.0

3 weeks agoEPSS 0%
HIGHPyPI

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode

gemini-bridge: 1.0.0 → 1.3.1

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature

thumbor: before 7.8.0

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

Thumbor has path traversal via post-validation URL decoding bypass in file_loader

thumbor: before 7.8.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in aiprepkit (PyPI)

Malicious code in aiprepkit (PyPI)

3 weeks ago
HIGHPyPI

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter

thumbor: before 7.8.0

3 weeks agoEPSS 0%
HIGHPyPI

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot

thumbor: before 7.8.0

3 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in asdk-plugin-legacy (PyPI)

Malicious code in asdk-plugin-legacy (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in asdk-plugin-alphagen (PyPI)

Malicious code in asdk-plugin-alphagen (PyPI)

3 weeks ago
HIGHPyPI

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

nltk: before 3.10.0

3 weeks ago
UNKNOWNPyPI

Malicious code in aiassistcore (PyPI)

Malicious code in aiassistcore (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in cognikit (PyPI)

Malicious code in cognikit (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in aichannel (PyPI)

Malicious code in aichannel (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in reguestsc (PyPI)

Malicious code in reguestsc (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in walmart-genai-trace (PyPI)

Malicious code in walmart-genai-trace (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ailaunchkit (PyPI)

Malicious code in ailaunchkit (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in catalogai (PyPI)

Malicious code in catalogai (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ml-nps-shared (PyPI)

Malicious code in ml-nps-shared (PyPI)

3 weeks ago
HIGHPyPI

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
HIGHPyPI

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

flyto-core: before 2.26.7

3 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in mcp-search-server (PyPI)

Malicious code in mcp-search-server (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ml-data-shared (PyPI)

Malicious code in ml-data-shared (PyPI)

3 weeks ago
HIGHPyPI

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

flyto-core: 2.26.6 → 2.26.7

3 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in ml-fdbk-shared (PyPI)

Malicious code in ml-fdbk-shared (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ai-perf-toolkit (PyPI)

Malicious code in ai-perf-toolkit (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in ml-shared (PyPI)

Malicious code in ml-shared (PyPI)

3 weeks ago
UNKNOWNPyPI

Malicious code in phabricator-client (PyPI)

Malicious code in phabricator-client (PyPI)

3 weeks ago
MODERATEPyPI

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: before 6.0.0

3 weeks agoEPSS 0%
HIGHPyPI

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive

penelope-shell-handler: before 0.20.0

3 weeks agoEPSS 0%
HIGHPyPI

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro: before 5.1.6

3 weeks agoEPSS 0%
HIGHPyPI

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

proot-distro: before 5.1.5

3 weeks agoEPSS 0%
HIGHPyPI

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from a

pip: before 26.2

3 weeks ago
MODERATEPyPI

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

matrix-commander: all versions

3 weeks ago
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

datamodel-code-generator: before 0.62.0

4 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

datamodel-code-generator: 0.25.0 → 0.60.1

4 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator: 0.9.1 → 0.61.0

4 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator: 0.9.1 → 0.61.0

4 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

datamodel-code-generator: 0.14.1 → 0.60.2

4 weeks agoEPSS 0%
CRITICALPyPI

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator: 0.11.6 → 0.64.0

4 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator: before 0.63.0

4 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

datamodel-code-generator: 0.17.0 → 0.60.2

4 weeks agoEPSS 0%
MEDIUMPyPI

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: before 0.63.0

4 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

datamodel-code-generator: 0.51.0 → 0.60.2

4 weeks agoEPSS 0%
HIGHPyPI

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi: 2.0.0 → 2.2.1

4 weeks agoEPSS 0%
HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator: 0.59.0 → 0.62.0

4 weeks agoEPSS 0%
CRITICALPyPI

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

datamodel-code-generator: 0.52.1 → 0.60.2

4 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in vtranalytic (PyPI)

Malicious code in vtranalytic (PyPI)

4 weeks ago
UNKNOWNPyPI

Malicious code in cfgzen (PyPI)

Malicious code in cfgzen (PyPI)

4 weeks ago
CRITICALPyPI

NLTK vulnerable to Eval Injection via collocations CLI arguments

NLTK vulnerable to Eval Injection via collocations CLI arguments

nltk: before 3.9.3

4 weeks ago
UNKNOWNPyPI

Malicious code in blessclient (PyPI)

Malicious code in blessclient (PyPI)

4 weeks ago
HIGHPyPI

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

bedrock-agentcore: before 1.18.1

4 weeks agoEPSS 0%
MODERATEPyPI

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

open-webui: 0.7.0 → 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

pymdown-extensions: before 11.0.0

4 weeks ago
HIGHPyPI

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

gitpython: before 3.1.55

4 weeks ago
CRITICALPyPI

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

gitpython: before 3.1.54

4 weeks ago
CRITICALPyPI

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

open-webui: before 0.10.0

4 weeks agoEPSS 0%
CRITICALPyPI

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: before 2026.7.4

4 weeks agoEPSS 0%
CRITICALPyPI

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

ray: before 2.56.0

4 weeks ago
HIGHPyPI

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

open-webui: before 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

open-webui: before 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

libp2p: all versions

4 weeks ago
HIGHPyPI

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

gitpython: before 3.1.54

4 weeks ago
MEDIUMPyPI

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

open-webui: 0.6.27 → 0.10.0

4 weeks agoEPSS 0%
CRITICALPyPI

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

gitpython: before 3.1.54

4 weeks ago
UNKNOWNPyPI

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.

datasets: before 5.0.1

4 weeks ago
HIGHPyPI

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

open-webui: 0.9.2 → 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

httplib2: before 0.32.0

4 weeks ago
UNKNOWNPyPI

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lo

nltk: before 3.9.3

4 weeks ago
HIGHPyPI

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

open-webui: 0.9.0 → 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

open-webui: before 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

open-webui: 0.6.16 → 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui: 0.9.6 → 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

open-webui: before 0.10.0

4 weeks agoEPSS 0%
CRITICALPyPI

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

gitpython: before 3.1.53

4 weeks agoEPSS 0%
UNKNOWNPyPI

Malicious code in discordnv (PyPI)

Malicious code in discordnv (PyPI)

4 weeks ago
CRITICALPyPI

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

awslabs-aws-api-mcp-server: 0.2.13 → 1.3.47

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

open-webui: before 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

open-webui: 0.9.6 → 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

open-webui: before 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: all versions

4 weeks ago
HIGHPyPI

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

awscli: before 1.44.78

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

open-webui: 0.8.12 → 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape

onnx: 1.3.0 → 1.22.0

4 weeks ago
HIGHPyPI

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)

open-webui: 0.9.5 → 0.10.0

4 weeks ago
MEDIUMPyPI

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

open-webui: 0.9.0 → 0.10.0

4 weeks agoEPSS 0%
MEDIUMPyPI

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

open-webui: 0.8.11 → 0.10.0

4 weeks agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: before 6.14.2

4 weeks agoEPSS 0%
MODERATEPyPI

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

pypdf: before 6.14.0

4 weeks agoEPSS 0%
HIGHPyPI

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

pypdf: before 6.14.1

4 weeks agoEPSS 0%
MODERATEPyPI

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: before 6.14.0

4 weeks agoEPSS 0%
HIGHPyPI

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

jupyterlab: 4.6.0 → 4.6.2

4 weeks ago
UNKNOWNPyPI

Malicious code in dev-helper-bg (PyPI)

Malicious code in dev-helper-bg (PyPI)

4 weeks ago
LOWPyPI

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

jupyterlab: 4.6.0 → 4.6.2

4 weeks ago
MODERATEPyPI

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

jupyterlab: 4.6.0 → 4.6.2

4 weeks ago
UNKNOWNPyPI

Malicious code in make-helper (PyPI)

Malicious code in make-helper (PyPI)

4 weeks ago
MODERATEPyPI

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

jupyterlab: 4.6.0 → 4.6.2

4 weeks ago
HIGHPyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

jupyterlab: 4.6.0 → 4.6.2

4 weeks ago
UNKNOWNPyPI

Malicious code in comp-colors (PyPI)

Malicious code in comp-colors (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in fluffy-octo-broccoli (PyPI)

Malicious code in fluffy-octo-broccoli (PyPI)

1 month ago
CRITICALPyPI

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

gitpython: before 3.1.51

1 month agoEPSS 1%
HIGHPyPI

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

gitpython: 3.1.50 → 3.1.51

1 month agoEPSS 0%
CRITICALPyPI

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

gitpython: before 3.1.51

1 month agoEPSS 1%
HIGHPyPI

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

pyasn1: before 0.6.4

1 month agoEPSS 0%
HIGHPyPI

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

gitpython: before 3.1.52

1 month agoEPSS 0%
HIGHPyPI

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

homeassistant: before 2026.6.0

1 month ago
HIGHPyPI

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`, allowing a remote attacker to crash any application using the reduced X86 Capstone library by supplying a crafted input containing the 4-byte sequence `0F 0F <modrm> <imm8>`. Versions 6.0.0-Alpha8 and 5.0.8 patch the issue.

capstone: before 5.0.8

1 month agoEPSS 0%
UNKNOWNPyPI

Malicious code in lebinfmt (PyPI)

Malicious code in lebinfmt (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in colorstack (PyPI)

Malicious code in colorstack (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in rasterkit-demo (PyPI)

Malicious code in rasterkit-demo (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in reimagined-broccoli (PyPI)

Malicious code in reimagined-broccoli (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in animated-octo-spoon (PyPI)

Malicious code in animated-octo-spoon (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in rasterkit (PyPI)

Malicious code in rasterkit (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh2 (PyPI)

Malicious code in hello-world-test-mh2 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kimichat (PyPI)

Malicious code in kimichat (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in automatic-octo-invention (PyPI)

Malicious code in automatic-octo-invention (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in neroteam-v1 (PyPI)

Malicious code in neroteam-v1 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in trongrider (PyPI)

Malicious code in trongrider (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in hello-world-test-mh3 (PyPI)

Malicious code in hello-world-test-mh3 (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in roles-royce (PyPI)

Malicious code in roles-royce (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in shark-e2e-bnsneo (PyPI)

Malicious code in shark-e2e-bnsneo (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in vantrala (PyPI)

Malicious code in vantrala (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in kimitalk (PyPI)

Malicious code in kimitalk (PyPI)

1 month ago
HIGHPyPI

vLLM denial of service via prompt embeds on M-RoPE models

vLLM denial of service via prompt embeds on M-RoPE models

vllm: 0.12.0 → 0.24.0

1 month ago
UNKNOWNPyPI

Malicious code in nemopush (PyPI)

Malicious code in nemopush (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in paperclip-ai (PyPI)

Malicious code in paperclip-ai (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in ml-core-airflow-auth (PyPI)

Malicious code in ml-core-airflow-auth (PyPI)

1 month ago
CRITICALPyPI

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

keras: before 3.12.3

1 month ago
UNKNOWNPyPI

Malicious code in data-parser-utils (PyPI)

Malicious code in data-parser-utils (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in tinkoff-cloud-apis-internal (PyPI)

Malicious code in tinkoff-cloud-apis-internal (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in python-devplatform-client (PyPI)

Malicious code in python-devplatform-client (PyPI)

1 month ago
UNKNOWNPyPI

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELE

SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope.

surrealdb: before 1.0.1

1 month ago
HIGHPyPI

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends

vllm: before 0.24.0

1 month ago
UNKNOWNPyPI

Malicious code in dwh-kafka-client (PyPI)

Malicious code in dwh-kafka-client (PyPI)

1 month ago
HIGHPyPI

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

prompty: before 2.0.0b2

1 month agoEPSS 1%
HIGHPyPI

vLLM has Remote DoS via Invalid Recovered Token Reinjection

vLLM has Remote DoS via Invalid Recovered Token Reinjection

vllm: 0.17.1 → 0.24.0

1 month ago
UNKNOWNPyPI

Malicious code in discord-telemetry (PyPI)

Malicious code in discord-telemetry (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in abseil-py (PyPI)

Malicious code in abseil-py (PyPI)

1 month ago
UNKNOWNPyPI

Malicious code in northstart-sdk (PyPI)

Malicious code in northstart-sdk (PyPI)

1 month ago
HIGHPyPI

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

ddtrace: before 4.8.2

1 month agoEPSS 0%
UNKNOWNPyPI

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.

lightning: all versions

1 month ago
MEDIUMPyPI

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

keras: before 3.12.3

1 month ago
HIGHPyPI

OpenStack Ironic has an Incorrect Resource Transfer Between Spheres

OpenStack Ironic has an Incorrect Resource Transfer Between Spheres

ironic-python-agent: before 26.1.6

1 month ago
HIGHPyPI

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

praisonaiagents: before 4.5.128

1 month agoEPSS 0%
CRITICALPyPI

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials

mcp-server-kubernetes: before 3.9.0

1 month ago
HIGHPyPI

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: before 0.22.0

1 month ago
MEDIUMPyPI

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the intended folder. The write is bounded to two directory levels above the output location and its target is determined by the operator's configuration, not the attacker.

bbot: 1.1.7 → 3.0.0

1 month ago
MEDIUMPyPI

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy versions of p7zip. Such an archive, downloaded and extracted during a scan (for example via filedownload), bypassed the guard and caused an attacker-controlled symlink to be written into the extraction directory. The effect is limited to planting the symlink (its tar

bbot: 2.3.1 → 3.0.0

1 month ago
UNKNOWNPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which can disclose adjacent memory or cause service degradation via a potential segmentation fault when the `vsi_buffer` property is accessed. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue

django: 5.2 → 5.2.16

1 month ago
MEDIUMPyPI

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

Django: DomainNameValidator permits newline characters that may enable HTTP header injection

django: before 5.2.16

1 month ago
MEDIUMPyPI

Django: GDALRaster may over-read heap memory when constructed from bytes

Django: GDALRaster may over-read heap memory when constructed from bytes

django: before 5.2.16

1 month ago
HIGHPyPI

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-p

apache-airflow: before 3.3.0

1 month ago
MEDIUMPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.

django: 5.2 → 5.2.16

1 month ago
MEDIUMPyPI

Django: cache middleware may expose private responses when unrelated request cookies are present

Django: cache middleware may expose private responses when unrelated request cookies are present

django: before 5.2.16

1 month ago
HIGHPyPI

apache-airflow DAG source authorization bypass exposes co-located DAG source

apache-airflow DAG source authorization bypass exposes co-located DAG source

apache-airflow: before 3.3.0

1 month ago
UNKNOWNPyPI

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.

django: 5.2 → 5.2.16

1 month ago
HIGHPyPI

Pulp incorrectly assigns RBAC permissions in tasks that create objects

Pulp incorrectly assigns RBAC permissions in tasks that create objects

pulpcore: all versions

1 month agoEPSS 1%
MODERATEPyPI

aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address

aiosmtplib: before 5.1.1

1 month ago
CRITICALPyPI

Keras: Lambda deserialization can bypass safe mode and execute code

Keras: Lambda deserialization can bypass safe mode and execute code

keras: before 3.12.3

1 month ago
HIGHPyPI

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: before 0.19.1

1 month ago
HIGHPyPI

MLflow: trace API endpoints lack proper authorization validators

MLflow: trace API endpoints lack proper authorization validators

mlflow: 2.14.0rc0 → 3.13.0rc0

1 month ago
HIGHPyPI

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

keras: before 3.12.3

1 month ago
HIGHPyPI

NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAF

NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal `../` sequences but fails to account for percent-encoded traversal sequences such as `..%2f`. The `url2pathname()` function decodes these sequences after the validation step, allowing an attacker to bypass the protection. This vulnerability enables an attacker to read arbitrary files accessible to the Python process b

nltk: all versions

1 month ago
HIGHPyPI

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras

MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.

msgpack: before 1.2.1

1 month ago
HIGHPyPI

Flawfinder output manipulation via untrusted filenames and source text

Flawfinder output manipulation via untrusted filenames and source text

flawfinder: before 2.0.20

2 months ago
MEDIUMPyPI

Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF

Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF

lemur: before 1.9.2

2 months ago
MEDIUMPyPI

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: 0.9.0 → 1.22.0

2 months ago
MODERATEPyPI

OctoPrint has XSS in its Suppressed Command Notifications

OctoPrint has XSS in its Suppressed Command Notifications

octoprint: before 1.11.8

2 months ago
HIGHPyPI

OctoPrint has possible file exfiltration via query parameters on upload endpoints

OctoPrint has possible file exfiltration via query parameters on upload endpoints

octoprint: before 1.11.8

2 months ago
MEDIUMPyPI

Keras: DiskIOStore permits path traversal through crafted layer names

Keras: DiskIOStore permits path traversal through crafted layer names

keras: before 3.12.3

2 months ago
HIGHPyPI

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

msgpack: before 1.2.1

2 months ago
HIGHPyPI

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

stigmem-node: before 0.9.0a12

2 months ago
HIGHPyPI

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: before 0.42.1

2 months agoEPSS 0%
MODERATEPyPI

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

jupyterlab: before 4.5.9

2 months agoEPSS 0%
HIGHPyPI

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

stigmem-node: before 0.9.0a12

2 months ago
HIGHPyPI

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stigmem-node: before 0.9.0a12

2 months ago
HIGHPyPI

OpenStack Horizon RC file generation does not escape special characters in project names

OpenStack Horizon RC file generation does not escape special characters in project names

horizon: all versions

2 months ago
HIGHPyPI

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

langchain: before 1.3.9

2 months ago
CRITICALPyPI

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

vllm: before 0.22.0

2 months ago
MEDIUMPyPI

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

pyjwt: 2.0.0 → 2.13.0

2 months agoEPSS 0%
MEDIUMPyPI

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

pyjwt: 2.0.0 → 2.13.0

2 months agoEPSS 0%
CRITICALPyPI

ChromaDB has a code injection vulnerability

ChromaDB has a code injection vulnerability

chromadb: ≥ 0.4.17

2 months ago
CRITICALPyPI

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

chromadb: ≥ 0.5.0

2 months ago
CRITICALPyPI

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

chromadb: ≥ 0.4.17

2 months ago
HIGHPyPI

Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

meta-ads-mcp: before 1.0.109

2 months ago
HIGHPyPI

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD) instead of the actual extraction destination. When the process runs with CWD set to `/`, which is common in Docker containers, CI/CD runners, and Jupyter environments, the validation boundary become

keras: before 3.14.0

2 months ago
HIGHPyPI

vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method

vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method

vllm: 0.8.0 → 0.19.0

2 months ago
HIGHPyPI

Keras archive extraction utilities allow path traversal and arbitrary file writes

Keras archive extraction utilities allow path traversal and arbitrary file writes

keras: before 3.14.0

2 months ago
HIGHPyPI

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processing `video/jpeg` data URLs, the method splits the base64 data string on commas to extract individual JPEG frames without enforcing a frame count limit. An attacker can exploit this by crafting a single API request containing thousands of comma-separated base64-encoded JPEG frames in a data URL, causin

vllm: 0.8.0 → 0.19.0

2 months ago
HIGHPyPI

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors

vllm: before 0.22.0

2 months ago
MEDIUMPyPI

Apache Airflow has a Path Traversal issue

Apache Airflow has a Path Traversal issue

apache-airflow-providers-samba: before 4.12.6

2 months agoEPSS 1%
MEDIUMPyPI

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-sam

apache-airflow-providers-samba: before 4.12.6

2 months agoEPSS 1%
HIGHPyPI

awxkit has a path traversal vulnerability

awxkit has a path traversal vulnerability

awxkit: all versions

2 months agoEPSS 0%
MEDIUMPyPI

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

zilliztech deep-searcher has an Incorrect Privilege Assignment issue

deepsearcher: all versions

2 months agoEPSS 0%
MEDIUMPyPI

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

MySQL MCP Server is Vulnerable to SQL Injection Through its mysql URI Handler

mysql-mcp-server: before 0.3.0

2 months agoEPSS 0%
MEDIUMPyPI

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

starlette: before 1.0.1

2 months ago
HIGHPyPI

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

OpenStack oslo.messaging does not verify RabbitMQ broker hostname during TLS handshake

oslo-messaging: ≥ 1.0.0

2 months agoEPSS 0%
MEDIUMPyPI

SGLang is Vulnerable to DoS via the data_hash Function

SGLang is Vulnerable to DoS via the data_hash Function

sglang: all versions

2 months ago
LOWPyPI

kas's late signature validation may allow unnoticed repository manipulations

kas's late signature validation may allow unnoticed repository manipulations

kas: 4.8 → 5.3

2 months ago
MEDIUMPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to than

django: 5.2 → 5.2.15

2 months ago
UNKNOWNPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-Control: public`, which allows remote attackers to read private cached responses via unauthenticated requests to the same URL. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to

django: 5.2 → 5.2.15

2 months ago
MEDIUMPyPI

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and salt argument), which allows a remote attacker to use a cookie in a context different from the one where it was signed, via distinct `(name, salt)` pairs that produce the same concatenation. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affec

django: 5.2 → 5.2.15

2 months ago
MEDIUMPyPI

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

Django: UpdateCacheMiddleware may disclose private cached responses by omitting Authorization from Vary

django: 5.2.0 → 5.2.15

2 months ago
MEDIUMPyPI

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank A

django: 5.2 → 5.2.15

2 months ago
MEDIUMPyPI

Django: signed cookies are vulnerable to salt namespace collisions

Django: signed cookies are vulnerable to salt namespace collisions

django: before 5.2.15

2 months ago
MEDIUMPyPI

Django: has_vary_header may expose cached responses when Vary values contain whitespace

Django: has_vary_header may expose cached responses when Vary values contain whitespace

django: before 5.2.15

2 months ago
MEDIUMPyPI

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling

django: before 5.2.15

2 months ago
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: all versions

2 months agoEPSS 0%
MEDIUMPyPI

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

nanobot-ai: before 0.2.1

2 months agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Injection issue

hermes-agent has an Injection issue

hermes-agent: before 0.15.0

2 months agoEPSS 0%
MEDIUMPyPI

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent: all versions

2 months agoEPSS 0%
LOWPyPI

kas checks out SHA-like git branches as valid commits

kas checks out SHA-like git branches as valid commits

kas: before 5.3

2 months ago
HIGHPyPI

stigmem-node's Postgres schema identifier handling required defensive quoting

stigmem-node's Postgres schema identifier handling required defensive quoting

stigmem-node: before 0.9.0a2

2 months ago
CRITICALPyPI

stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback

stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback

stigmem-node: before 0.9.0a2

2 months ago
CRITICALPyPI

stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation

stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation

stigmem-node: before 0.9.0a2

2 months ago
HIGHPyPI

stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment

stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment

stigmem-node: before 0.9.0a2

2 months ago
CRITICALPyPI

PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

praisonai-platform: before 0.1.4

2 months ago
CRITICALPyPI

stigmem-node's federation peer registration lacked explicit out-of-band approval

stigmem-node's federation peer registration lacked explicit out-of-band approval

stigmem-node: before 0.9.0a2

2 months ago
HIGHPyPI

stigmem-node's federation peer token timestamp validation may reject valid peer tokens

stigmem-node's federation peer token timestamp validation may reject valid peer tokens

stigmem-node: before 0.9.0a2

2 months ago
HIGHPyPI

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler

aiosend: before 3.0.7

3 months ago
LOWPyPI

justhtml introduces denial-of-service hardening

justhtml introduces denial-of-service hardening

justhtml: before 1.18.0

3 months ago
CRITICALPyPI

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

gitpython: before 3.1.50

3 months agoEPSS 0%
HIGHPyPI

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`

jupyter-server: before 2.18.0

3 months agoEPSS 0%
HIGHPyPI

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

jupyter-server: before 2.18.0

3 months agoEPSS 1%
CRITICALPyPI

OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere

OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere

ironic-python-agent: 1.0.0 → 11.6.0

3 months ago
MODERATEPyPI

justhtml has sanitization bypass in custom policies and programmatic DOM

justhtml has sanitization bypass in custom policies and programmatic DOM

justhtml: before 1.17.0

4 months ago
LOWPyPI

Multiple security fixes in justhtml

Multiple security fixes in justhtml

justhtml: before 1.16.0

4 months ago
MODERATEPyPI

justhtml includes multiple security fixes

justhtml includes multiple security fixes

justhtml: before 1.15.0

4 months ago
LOWPyPI

justhtml: Mutation XSS with custom foreign-namespace sanitization policies

justhtml: Mutation XSS with custom foreign-namespace sanitization policies

justhtml: 1.13.0 → 1.14.0

4 months ago
CRITICALPyPI

MONAI: Unsafe functions lead to pickle deserialization rce

MONAI: Unsafe functions lead to pickle deserialization rce

monai: before 1.6.0

4 months ago
HIGHPyPI

vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing

vLLM: Denial of Service via Unbounded Frame Count in video/jpeg Base64 Processing

vllm: 0.7.0 → 0.19.0

4 months ago
MODERATEPyPI

openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys

openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt has no owner verification on key revocation — any client can revoke any key

openssl-encrypt has no owner verification on key revocation — any client can revoke any key

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt has CORS wildcard with allow_credentials=True in standalone servers

openssl-encrypt has CORS wildcard with allow_credentials=True in standalone servers

openssl-encrypt: before 1.4.0

4 months ago
HIGHPyPI

ONNX: TOCTOU arbitrary file read/write in save_external_dat

ONNX: TOCTOU arbitrary file read/write in save_external_dat

onnx: before 1.21.0

4 months ago
MODERATEPyPI

openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection

openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification

openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt has visible password in process list via --password CLI argument

openssl-encrypt has visible password in process list via --password CLI argument

openssl-encrypt: before 1.4.0

4 months ago
MODERATEPyPI

openssl-encrypt silently skips schema validation when jsonschema library is not installed

openssl-encrypt silently skips schema validation when jsonschema library is not installed

openssl-encrypt: before 1.4.0

4 months ago
CRITICALPyPI

openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart

openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart

openssl-encrypt: before 1.4.0

4 months ago
HIGHPyPI

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

JustHTML is vulnerable to XSS via code fence breakout in <pre> content

justhtml: before 1.13.0

5 months ago
MODERATEPyPI

Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS

Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS

nltk: all versions

5 months ago
MODERATEPyPI

JustHTML has a Sanitizer Bypass (in Markdown)

JustHTML has a Sanitizer Bypass (in Markdown)

justhtml: before 1.12.0

5 months ago
MODERATEPyPI

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)

justhtml: before 1.12.0

5 months ago
HIGHPyPI

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

Uncontrolled recursion DoS in JustHTML() via deeply nested HTML

justhtml: before 1.10.0

5 months ago
HIGHPyPI

Black: Arbitrary file writes from unsanitized user input in cache file name

Black: Arbitrary file writes from unsanitized user input in cache file name

black: 24.3.0 → 26.3.1

5 months agoEPSS 1%
CRITICALPyPI

vLLM affected by RCE via auto_map dynamic module loading during model initialization

vLLM affected by RCE via auto_map dynamic module loading during model initialization

vllm: 0.10.1 → 0.14.0

7 months ago
MODERATEPyPI

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard

distributed: before 2026.1.0

7 months ago
HIGHPyPI

pyasn1 has a DoS vulnerability in decoder

pyasn1 has a DoS vulnerability in decoder

pyasn1: 0.6.1 → 0.6.2

7 months ago
HIGHPyPI

XGrammar affected by Denial of Service by infinite recursion grammars

XGrammar affected by Denial of Service by infinite recursion grammars

xgrammar: before 0.1.21

1 year ago
MODERATEPyPI

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Apache Superset data query improperly discloses database schema information to low-privileged guest user

apache-superset: before 4.1.3.post1

1 year ago
CRITICALPyPI

num2words subjected to phishing attack, two versions published containing malware

num2words subjected to phishing attack, two versions published containing malware

num2words: ≥ 0.5.15

1 year ago
HIGHPyPI

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookData requests, bypassing the intended extension-based check.

dagster-ge: all versions

1 year agoEPSS 1%
HIGHPyPI

vLLM allows clients to crash the openai server with invalid regex

vLLM allows clients to crash the openai server with invalid regex

vllm: 0.8.0 → 0.9.0

1 year ago
MEDIUMPyPI

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

Potential Timing Side-Channel Vulnerability in vLLM’s Chunk-Based Prefix Caching

vllm: before 0.9.0

1 year ago
MEDIUMPyPI

vLLM vulnerable to Regular Expression Denial of Service

vLLM vulnerable to Regular Expression Denial of Service

vllm: 0.6.3 → 0.9.0

1 year ago
MEDIUMPyPI

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

vLLM has a Weakness in MultiModalHasher Image Hashing Implementation

vllm: 0.7.0 → 0.9.0

1 year ago
HIGHPyPI

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vLLM DOS: Remotely kill vllm over http with invalid JSON schema

vllm: 0.8.0 → 0.9.0

1 year ago
HIGHPyPI

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

vLLM Tool Schema allows DoS via Malformed pattern and type Fields

vllm: 0.8.0 → 0.9.0

1 year ago
HIGHPyPI

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

vLLM has a Regular Expression Denial of Service (ReDoS, Exponential Complexity) Vulnerability in `pythonic_tool_parser.py`

vllm: 0.6.4 → 0.9.0

1 year ago
CRITICALPyPI

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vllm: 0.6.5 → 0.8.5

1 year ago
CRITICALPyPI

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

vllm: 0.5.2 → 0.10.0

1 year ago
HIGHPyPI

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

vllm: 0.5.2 → 0.8.5

1 year ago
CRITICALPyPI

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vllm: 0.6.5 → 0.8.5

1 year ago
HIGHPyPI

vLLM: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

vLLM: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

vllm: 0.8.0 → 0.8.5

1 year ago
MEDIUMPyPI

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

transformers: before 4.50.0

1 year ago
CRITICALPyPI

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

vllm: before 0.8.0

1 year ago
CRITICALPyPI

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

torch: before 2.6.0

1 year ago
MEDIUMPyPI

PyTorch Improper Resource Shutdown or Release vulnerability

PyTorch Improper Resource Shutdown or Release vulnerability

torch: before 2.8.0

1 year ago
HIGHPyPI

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory

xgrammar: before 0.1.18

1 year ago
CRITICALPyPI

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

Apache Airflow Common SQL Provider Vulnerable to SQL Injection

apache-airflow-providers-common-sql: before 1.24.1

1 year ago
CRITICALPyPI

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object

vllm: all versions

1 year ago
MEDIUMPyPI

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

Transformers Regular Expression Denial of Service (ReDoS) vulnerability

transformers: before 4.48.0

1 year ago
CRITICALPyPI

vLLM Deserialization of Untrusted Data vulnerability

vLLM Deserialization of Untrusted Data vulnerability

vllm: all versions

1 year ago
CRITICALPyPI

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints

vllm: all versions

1 year ago
HIGHPyPI

vLLM denial of service via outlines unbounded cache on disk

vLLM denial of service via outlines unbounded cache on disk

vllm: before 0.8.0

1 year ago
CRITICALPyPI

vLLM Allows Remote Code Execution via Mooncake Integration

vLLM Allows Remote Code Execution via Mooncake Integration

vllm: 0.6.5 → 0.8.0

1 year ago
HIGHPyPI

ray vulnerable to Insertion of Sensitive Information into Log File

ray vulnerable to Insertion of Sensitive Information into Log File

ray: before 2.43.0

1 year ago
MEDIUMPyPI

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vllm: before 0.7.2

1 year ago
CRITICALPyPI

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: before 0.7.0

1 year ago
HIGHPyPI

vLLM denial of service vulnerability

vLLM denial of service vulnerability

vllm: before 0.5.5

1 year ago
HIGHPyPI

vLLM Denial of Service via the best_of parameter

vLLM Denial of Service via the best_of parameter

vllm: all versions

1 year ago
HIGHPyPI

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

aiohttp: before 3.9.4

2 years ago
HIGHPyPI

Pydantic regular expression denial of service

Pydantic regular expression denial of service

pydantic: 2.0.0 → 2.4.0

2 years ago
CRITICALPyPI

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

airflow-diagrams: all versions

2 years agoEPSS 1%
HIGHPyPI

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

setuptools: before 65.5.1

3 years ago
MODERATEPyPI

OpenStack Neutron Improper Input Validation vulnerability

OpenStack Neutron Improper Input Validation vulnerability

neutron: 2000 → 2014.2.4

4 years ago

Tooling for PyPI

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexMavenNuGetPackagistRubyGemscrates.ionpm