Tagged “osv”
CVEs tagged osv, newest first.
5683 CVEsRSS
MAL-2026-10484NoneMalicious code in browser-use-headless (PyPI)
Malicious code in browser-use-headless (PyPI)
MAL-2026-10441NoneMalicious code in turbocalcng (PyPI)
Malicious code in turbocalcng (PyPI)
CVE-2026-56074Medium· 5.5PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-15529Medium· 6.3A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…
MAL-2026-10215NoneMalicious code in fast-dotenv (PyPI)
Malicious code in fast-dotenv (PyPI)
MAL-2026-10213NoneMalicious code in pipspeed (PyPI)
Malicious code in pipspeed (PyPI)
MAL-2026-10197NoneMalicious code in metemask-sdk (PyPI)
Malicious code in metemask-sdk (PyPI)
MAL-2026-10196NoneMalicious code in jupiter-sdk (PyPI)
Malicious code in jupiter-sdk (PyPI)
MAL-2026-10195NoneMalicious code in eth-agent (PyPI)
Malicious code in eth-agent (PyPI)
MAL-2026-10194NoneMalicious code in solidity-dev (PyPI)
Malicious code in solidity-dev (PyPI)
MAL-2026-10193NoneMalicious code in py-base58 (PyPI)
Malicious code in py-base58 (PyPI)
MAL-2026-10192NoneMalicious code in defi-tools (PyPI)
Malicious code in defi-tools (PyPI)
MAL-2026-10191NoneMalicious code in data-harvester (PyPI)
Malicious code in data-harvester (PyPI)
CVE-2026-56260Critical· 9.1Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supp…
RUSTSEC-2026-0206None`rustybuzz` is unmaintained
`rustybuzz` is unmaintained
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…
CVE-2026-59162High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…
CVE-2026-59161High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…
GHSA-wm45-qh3g-v83fHigh· 7.7mcp-atlassian: Arbitrary server-side file read via attachment upload
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-489g-7rxv-6c8qMedium· 6.5MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
MAL-2026-10139NoneMalicious code in turbocalc (PyPI)
Malicious code in turbocalc (PyPI)
MAL-2026-10119NoneMalicious code in sankislayer (PyPI)
Malicious code in sankislayer (PyPI)
MAL-2026-10100NoneMalicious code in proxy-check-i (PyPI)
Malicious code in proxy-check-i (PyPI)
CVE-2026-49851High· 7.5Mistune: Potential DoS via quadratic-time parsing in parse_link_text
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
MAL-2026-10091NoneMalicious code in qlinforge (PyPI)
Malicious code in qlinforge (PyPI)
MAL-2026-10020NoneMalicious code in playwrightr (PyPI)
Malicious code in playwrightr (PyPI)
CVE-2026-49476High· 7.5Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
CVE-2026-14967Low· 3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…
BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…
CVE-2026-14966Low· 3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…
BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…
RUSTSEC-2026-0220NoneUint shift operations: incorrect overflow flags and truncated shift amounts
Uint shift operations: incorrect overflow flags and truncated shift amounts