instructlab vulnerabilities
CVEs whose affected-version data names the instructlab package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-6859High· 8.8InstructLab Includes Functionality from Untrusted Control Sphere
InstructLab Includes Functionality from Untrusted Control Sphere
▾ Twilightinstructlab · instructlabEPSS 0.44%via OSV
CVE-2026-6855High· 7.1InstructLab vulnerable to Path Traversal
InstructLab vulnerable to Path Traversal
▾ Twilightinstructlab · instructlabEPSS 0.16%via OSV