Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-55099High· 7.5icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
CVE-2026-54338Medium· 5.3JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
CVE-2026-12210Medium· 4.7utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
CVE-2026-55419Medium· 5.3reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-vwf3-4xxj-qg6hHighmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
CVE-2026-55618Medium· 6.5eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
CVE-2026-55619Medium· 5.3eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
CVE-2026-55620High· 7.5eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
GHSA-9qhg-99ww-9mqcHigh· 8.2utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
GHSA-ppx3-28rw-8fpfMedium· 4.7utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
GHSA-8cp3-qxj6-px34High· 7.1utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
CVE-2026-55640Critical· 9.1nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( d…
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
CVE-2026-55571High· 8.2djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
CVE-2026-55585High· 8.8qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
CVE-2026-55529Medium· 6.9PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
CVE-2026-55528High· 8.2praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
CVE-2026-55531Medium· 6.5PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
CVE-2026-55526High· 8.5praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55534High· 8.6PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
CVE-2026-55530Medium· 6.1praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-55538High· 7.3PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
CVE-2026-55537High· 7.1PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
CVE-2026-55535Medium· 6.8PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
CVE-2026-55541HighPraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
CVE-2026-55539High· 8.6PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
CVE-2026-55533High· 8.2PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
CVE-2026-55532High· 7.6PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
CVE-2026-55536Critical· 9.1PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)