VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

GHSA-x5cx-w6p2-mxf2Medium· 6.5
1mo ago

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-jm5p-837g-rv8gMedium· 6.5
1mo ago

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-9w56-46f6-3qhxMedium· 5.5
1mo ago

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

▾ Sunlitasteval · astevalvia OSV
CVE-2026-54449High· 8.8
1mo ago

LangBot is a global IM bot platform designed for LLMs

LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tool…

▾ Twilightlangbot · langbotEPSS 0.72%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
GHSA-w672-239g-c3grHigh· 6.5
1mo ago

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-wv46-xpj8-pw53High· 8.8
1mo ago

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-7jx3-jqcp-hhgcHigh· 8.1
1mo ago

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-3vrx-526r-64rmHigh· 8.2
1mo ago

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-298h-jpq4-m665High· 7.5
1mo ago

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
MAL-2026-14308None
1mo ago

Malicious code in libasync (PyPI)

Malicious code in libasync (PyPI)

▾ Sunlitlibasync · libasyncvia OSV
MAL-2026-14306None
1mo ago

Malicious code in rc4-secure (PyPI)

Malicious code in rc4-secure (PyPI)

▾ Sunlitrc4-secure · rc4-securevia OSV
CVE-2026-76237High
1mo ago

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count qu…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-76245High
1mo ago

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliab…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.24%via NVD
CVE-2026-76236High
1mo ago

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant,…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-76220High· 8.8
1mo ago

gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)

A flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.91%via CSAF
CVE-2026-76241High
1mo ago

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by les…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.11%via NVD
CVE-2026-76244Critical
1mo ago

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while bindi…

▾ Midnightstigmem-node · stigmem-nodeEPSS 0.27%via NVD
CVE-2026-76221High· 8.8
1mo ago

gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)

A flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary gi…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.77%via CSAF
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-76243Critical
1mo ago

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside…

▾ Midnightstigmem-node · stigmem-nodeEPSS 0.56%via NVD
CVE-2026-76242Critical
1mo ago

stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step

stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial reg…

▾ Midnightstigmem-node · stigmem-nodeEPSS 0.35%via NVD
CVE-2026-76218High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)

A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containin…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.83%via CSAF
CVE-2026-76240High
1mo ago

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sc…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.38%via NVD
CVE-2026-76238High
1mo ago

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all te…

stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all te…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-76239Medium· 6.3
1mo ago

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact…

▾ Sunlitstigmem-node · stigmem-nodeEPSS 0.32%via NVD
CVE-2026-76219High· 8.1
1mo ago

gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)

A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, …

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.54%via CSAF
CVE-2026-53951High
1mo ago

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-53964High· 7.2
1mo ago

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

▾ Twilightdocument-merge-service · document-merge-servicevia OSV
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
CVEs tagged “pip” — page 17 · VulnSea