VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-73417High· 8.3
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an ov…

▾ Twilightjupyterlab · jupyterlabEPSS 0.75%via NVD
CVE-2026-73568High· 7.5
1mo ago

py-libp2p is the Python implementation of the libp2p networking stack

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…

▾ Twilightlibp2p · libp2pEPSS 0.49%via NVD
CVE-2026-73416Medium
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jup…

▾ Sunlitjupyterlab · jupyterlabEPSS 0.66%via NVD
CVE-2026-73652High
1mo ago

vantage6 is an open-source infrastructure for privacy preserving analysis

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorith…

▾ Twilightvantage6 · vantage6EPSS 0.35%via NVD
CVE-2026-73559Medium· 6.5
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list…

▾ Sunlitvllm · vllmEPSS 0.55%via NVD
CVE-2026-54249Medium· 6.8
1mo ago

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials

▾ Sunlitpydantic-ai-slim · pydantic-ai-slimEPSS 0.32%via GHSA
GHSA-rm43-82j9-r4mjHigh
1mo ago

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
CVE-2026-59714High· 7.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM ch…

▾ Twilightopen-webui · open-webuiEPSS 0.48%via NVD
CVE-2026-45774Medium
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them wi…

▾ Sunlitcompliance-trestle · compliance-trestleEPSS 0.54%via NVD
CVE-2026-45725High
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache fil…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.47%via NVD
CVE-2026-48099High· 7.1
1mo ago

WsgiDAV is a generic and extendable WebDAV server based on WSGI

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path lay…

▾ Twilightwsgidav · wsgidavEPSS 0.41%via NVD
CVE-2026-73262Medium· 5.4
1mo ago

Prowler is a cloud security platform

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTM…

▾ Sunlitprowler · prowlerEPSS 0.30%via NVD
CVE-2026-73295Medium· 5.4
1mo ago

Material for MkDocs is a powerful documentation framework built on top of MkDocs

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-s…

▾ Sunlitmkdocs-material · mkdocs-materialEPSS 0.33%via NVD
CVE-2026-68868Medium· 6.5
1mo ago

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

▾ Sunlitapache · apache-airflow-providers-googleEPSS 0.60%via NVD
CVE-2026-68970Medium· 6.5
1mo ago

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserial…

▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2026-68969Medium· 6.5
1mo ago

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`)

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking rec…

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-68968High· 7.5
1mo ago

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as …

▾ Twilightapache · airflowEPSS 0.75%via NVD
CVE-2026-68076Medium· 5.4
1mo ago

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a …

▾ Sunlitapache · airflowEPSS 0.62%via NVD
CVE-2026-67587High· 8.8
1mo ago

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default…

▾ Twilightapache · airflowEPSS 1.2%via NVD
CVE-2026-67260High· 7.3
1mo ago

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who con…

▾ Twilightapache · airflowEPSS 1.4%via NVD
CVE-2026-59244Medium· 6.5
1mo ago

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a tem…

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a tem…

▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2026-54183Medium· 4.3
1mo ago

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an …

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-73415High· 8.0
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.74%via NVD
CVE-2026-73498High· 7.7
1mo ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassia…

▾ Twilightmcp-atlassian · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-9318Medium· 5.4
1mo ago

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated …

▾ Sunlittablib · tablibEPSS 0.30%via NVD
CVE-2026-73229Medium· 4.3
1mo ago

Django REST framework is a powerful and flexible toolkit for building Web APIs

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.37%via NVD
CVE-2026-73228Medium· 5.3
1mo ago

Django REST framework is a toolkit for building Web APIs

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser f…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.56%via NVD
MAL-2026-13757None
1mo ago

Malicious code in telebot-pro (PyPI)

Malicious code in telebot-pro (PyPI)

▾ Sunlittelebot-pro · telebot-provia OSV
MAL-2026-13756None
1mo ago

Malicious code in joule-sbx-poc (PyPI)

Malicious code in joule-sbx-poc (PyPI)

▾ Sunlitjoule-sbx-poc · joule-sbx-pocvia OSV
MAL-2026-13732None
1mo ago

Malicious code in joule-btp-extension (PyPI)

Malicious code in joule-btp-extension (PyPI)

▾ Sunlitjoule-btp-extension · joule-btp-extensionvia OSV
CVEs tagged “pip” — page 21 · VulnSea