local-deep-research vulnerabilities
CVEs whose affected-version data names the local-deep-research package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-46526Medium· 5.0local-deep-research has an SSRF bypass in `safe_get`
local-deep-research has an SSRF bypass in `safe_get`
▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.25%via OSV
CVE-2026-43979Medium· 5.0local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.26%via OSV
CVE-2025-67743Medium· 6.3Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
▾ Sunlitlocal-deep-research · local-deep-researchEPSS 0.32%via OSV