VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4636 CVEsRSS

MAL-2026-13490None
1mo ago

Malicious code in fast-hashes (PyPI)

Malicious code in fast-hashes (PyPI)

▾ Sunlitfast-hashes · fast-hashesvia OSV
MAL-2026-13489None
1mo ago

Malicious code in pydanticc (PyPI)

Malicious code in pydanticc (PyPI)

▾ Sunlitpydanticc · pydanticcvia OSV
MAL-2026-13488None
1mo ago

Malicious code in idnna (PyPI)

Malicious code in idnna (PyPI)

▾ Sunlitidnna · idnnavia OSV
MAL-2026-13487None
1mo ago

Malicious code in flasq (PyPI)

Malicious code in flasq (PyPI)

▾ Sunlitflasq · flasqvia OSV
MAL-2026-13486None
1mo ago

Malicious code in fastapii (PyPI)

Malicious code in fastapii (PyPI)

▾ Sunlitfastapii · fastapiivia OSV
CVE-2026-71852Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
GHSA-4gmw-gg2m-w46pHigh· 8.1
1mo ago

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-9rj7-rf2p-w77rHigh· 7.5
1mo ago

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-hh9p-6wh2-4mfcMedium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ SunlitGitPython · GitPythonvia GHSA
GHSA-hmq2-w58f-27jcHigh· 8.2
1mo ago

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-jm78-9fvv-mhgrHigh· 8.8
1mo ago

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-wvpp-8hx9-p66jHigh· 8.8
1mo ago

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-48169High· 8.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.44%via NVD
CVE-2026-48039Critical· 9.1
1mo ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…

▾ Midnightmeta-ads-mcp · meta-ads-mcpEPSS 0.59%via NVD
CVE-2026-64640NonePoC
1mo ago

Apache Polaris did not consistently validate storage locations supplied during table and view registration.

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration…

▾ Twilightapache-polaris · apache-polarisEPSS 0.49%via OSV
MAL-2026-13473None
1mo ago

Malicious code in alphalend-layouts (PyPI)

Malicious code in alphalend-layouts (PyPI)

▾ Sunlitalphalend-layouts · alphalend-layoutsvia OSV
MAL-2026-13472None
1mo ago

Malicious code in alphalend-abi (PyPI)

Malicious code in alphalend-abi (PyPI)

▾ Sunlitalphalend-abi · alphalend-abivia OSV
CVE-2026-67422High· 7.5
1mo ago

pymdown-extensions is a collection of extensions for the Python Markdown library

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can parti…

▾ TwilightRed Hat · Red Hat Developer HubEPSS 0.61%via NVD
CVE-2026-71554Medium· 5.3PoC
1mo ago

h2 is a pure-Python implementation of a HTTP/2 protocol stack

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where the co…

▾ Twilighth2 · h2EPSS 0.42%via NVD
CVE-2026-18654Medium· 6.8
1mo ago

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

▾ Sunlitawscli · awscliEPSS 0.29%via OSV
CVE-2026-71433Medium· 5.3
1mo ago

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarc…

▾ Sunlitlanggraph-checkpoint-postgres · langgraph-checkpoint-postgresEPSS 0.36%via NVD
MAL-2026-13426None
1mo ago

Malicious code in xayoub-xctxteam (PyPI)

Malicious code in xayoub-xctxteam (PyPI)

▾ Sunlitxayoub-xctxteam · xayoub-xctxteamvia OSV
MAL-2026-13386None
1mo ago

Malicious code in decapod-common (PyPI)

Malicious code in decapod-common (PyPI)

▾ Sunlitdecapod-common · decapod-commonvia OSV
CVE-2026-70646High· 7.5
1mo ago

aiosend is a synchronous and asynchronous Crypto Pay API client

aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to f…

▾ Twilightaiosend · aiosendEPSS 0.64%via NVD
CVE-2026-55524High· 7.5
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.24%via NVD
CVE-2026-55522High· 7.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.22%via NVD
CVE-2026-55523High
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and b…

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.47%via NVD
CVE-2026-71211High· 7.1PoC
1mo ago

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim

MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy…

▾ Midnightmlflow · mlflowEPSS 0.29%via NVD
MAL-2026-13380None
1mo ago

Malicious code in uncrypt (PyPI)

Malicious code in uncrypt (PyPI)

▾ Sunlituncrypt · uncryptvia OSV
MAL-2026-13373None
1mo ago

Malicious code in solana-sniper-bot (PyPI)

Malicious code in solana-sniper-bot (PyPI)

▾ Sunlitsolana-sniper-bot · solana-sniper-botvia OSV
CVEs tagged “pip” — page 23 · VulnSea