VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-55099High· 7.5
1mo ago

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

▾ Twilighticalendar · icalendarEPSS 0.63%via OSV
CVE-2026-54338Medium· 5.3
1mo ago

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

▾ Sunlitjupyterhub · jupyterhubEPSS 0.44%via OSV
CVE-2026-12210Medium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlEPSS 0.23%via OSV
CVE-2026-55419Medium· 5.3
1mo ago

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

▾ Sunlitreachy-mini · reachy-miniEPSS 0.48%via OSV
GHSA-vwf3-4xxj-qg6hHigh
1mo ago

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

▾ Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA
CVE-2026-55618Medium· 6.5
1mo ago

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

▾ Sunliteml-parser · eml-parserEPSS 0.52%via OSV
CVE-2026-55619Medium· 5.3
1mo ago

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

▾ Sunliteml-parser · eml-parserEPSS 0.52%via OSV
CVE-2026-55620High· 7.5
1mo ago

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

▾ Twilighteml-parser · eml-parserEPSS 0.63%via OSV
GHSA-9qhg-99ww-9mqcHigh· 8.2
1mo ago

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

▾ Twilightutcp-http · utcp-httpvia GHSA
GHSA-ppx3-28rw-8fpfMedium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlvia GHSA
GHSA-8cp3-qxj6-px34High· 7.1
1mo ago

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

▾ Twilightutcp-http · utcp-httpvia GHSA
CVE-2026-55640Critical· 9.1
1mo ago

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( d…

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

▾ Midnightnextcloud-mcp-server · nextcloud-mcp-serverEPSS 0.73%via OSV
CVE-2026-55571High· 8.2
1mo ago

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

▾ Twilightdjust · djustEPSS 0.51%via OSV
CVE-2026-55585High· 8.8
1mo ago

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

▾ Twilightqwed · qwedEPSS 0.78%via OSV
CVE-2026-55529Medium· 6.9
1mo ago

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via OSV
CVE-2026-55528High· 8.2
1mo ago

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.49%via OSV
CVE-2026-55531Medium· 6.5
1mo ago

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

▾ Sunlitpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55526High· 8.5
1mo ago

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via OSV
CVE-2026-55534High· 8.6
1mo ago

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55530Medium· 6.1
1mo ago

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.17%via OSV
CVE-2026-55540High· 7.1
1mo ago

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

▾ Twilightpraisonai · praisonaiEPSS 0.39%via OSV
CVE-2026-55538High· 7.3
1mo ago

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55537High· 7.1
1mo ago

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

▾ Twilightpraisonai · praisonaiEPSS 0.27%via OSV
CVE-2026-55535Medium· 6.8
1mo ago

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

▾ Sunlitpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-55541High
1mo ago

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

▾ Twilightpraisonai · praisonaiEPSS 0.48%via OSV
CVE-2026-55527High· 7.1
1mo ago

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.48%via OSV
CVE-2026-55539High· 8.6
1mo ago

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-55533High· 8.2
1mo ago

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-55532High· 7.6
1mo ago

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

▾ Twilightpraisonai · praisonaiEPSS 0.20%via OSV
CVE-2026-55536Critical· 9.1
1mo ago

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

▾ Midnightpraisonai · praisonaiEPSS 0.52%via OSV
CVEs tagged “pip” — page 14 · VulnSea