VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-13372None
1mo ago

Malicious code in eth-account-wallet (PyPI)

Malicious code in eth-account-wallet (PyPI)

▾ Sunliteth-account-wallet · eth-account-walletvia OSV
MAL-2026-13362None
1mo ago

Malicious code in mnemonic-py (PyPI)

Malicious code in mnemonic-py (PyPI)

▾ Sunlitmnemonic-py · mnemonic-pyvia OSV
MAL-2026-13361None
1mo ago

Malicious code in defi-sdk-py (PyPI)

Malicious code in defi-sdk-py (PyPI)

▾ Sunlitdefi-sdk-py · defi-sdk-pyvia OSV
MAL-2026-12503None
1mo ago

Malicious code in numpyp (PyPI)

Malicious code in numpyp (PyPI)

▾ Sunlitnumpyp · numpypvia OSV
MAL-2026-12502None
1mo ago

Malicious code in gcli-control (PyPI)

Malicious code in gcli-control (PyPI)

▾ Sunlitgcli-control · gcli-controlvia OSV
MAL-2026-12083None
1mo ago

Malicious code in crypto-wallet-sdk (PyPI)

Malicious code in crypto-wallet-sdk (PyPI)

▾ Sunlitcrypto-wallet-sdk · crypto-wallet-sdkvia OSV
MAL-2026-12082None
1mo ago

Malicious code in crypto-trading-toolkit (PyPI)

Malicious code in crypto-trading-toolkit (PyPI)

▾ Sunlitcrypto-trading-toolkit · crypto-trading-toolkitvia OSV
MAL-2026-12081None
1mo ago

Malicious code in bitcoinlib-py (PyPI)

Malicious code in bitcoinlib-py (PyPI)

▾ Sunlitbitcoinlib-py · bitcoinlib-pyvia OSV
MAL-2026-12080None
1mo ago

Malicious code in bip39-py (PyPI)

Malicious code in bip39-py (PyPI)

▾ Sunlitbip39-py · bip39-pyvia OSV
CVE-2026-15830None
1mo ago

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as …

▾ Sunlitdjango · djangoEPSS 0.76%via OSV
CVE-2026-70489Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of…

▾ Sunlitopenwebui · open_webuiEPSS 0.57%via NVD
CVE-2026-70490Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never appl…

▾ Sunlitopenwebui · open_webuiEPSS 0.28%via NVD
CVE-2026-70491Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py r…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-70492High· 8.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes K…

▾ Twilightopenwebui · open_webuiEPSS 0.40%via NVD
CVE-2026-70493Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a c…

▾ Sunlitopenwebui · open_webuiEPSS 0.59%via NVD
CVE-2026-70494High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a sha…

▾ Twilightopenwebui · open_webuiEPSS 0.55%via NVD
CVE-2026-70481Medium· 5.4PoC
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…

▾ Twilightopenwebui · open_webuiEPSS 0.43%via NVD
CVE-2026-70482High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it b…

▾ Twilightopenwebui · open_webuiEPSS 0.57%via NVD
CVE-2026-70483Low· 3.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any au…

▾ Sunlitopenwebui · open_webuiEPSS 0.46%via NVD
CVE-2026-70480Medium· 4.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser withou…

▾ Sunlitopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-70484Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.i…

▾ Sunlitopenwebui · open_webuiEPSS 0.41%via NVD
CVE-2026-70485High· 7.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the litera…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-70486High· 8.2
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-70488Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids su…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-70487Medium· 5.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read a…

▾ Sunlitopenwebui · open_webuiEPSS 0.42%via NVD
CVE-2026-54020Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…

▾ Sunlitopenwebui · open_webuiEPSS 0.25%via NVD
CVE-2026-70479High· 7.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…

▾ Twilightopenwebui · open_webuiEPSS 0.47%via NVD
MAL-2026-11521None
1mo ago

Malicious code in psbt-helpers (PyPI)

Malicious code in psbt-helpers (PyPI)

▾ Sunlitpsbt-helpers · psbt-helpersvia OSV
MAL-2026-11520None
1mo ago

Malicious code in psbt-utils (PyPI)

Malicious code in psbt-utils (PyPI)

▾ Sunlitpsbt-utils · psbt-utilsvia OSV
MAL-2026-11519None
1mo ago

Malicious code in launchdarkly-ai-server-sdk (PyPI)

Malicious code in launchdarkly-ai-server-sdk (PyPI)

▾ Sunlitlaunchdarkly-ai-server-sdk · launchdarkly-ai-server-sdkvia OSV
CVEs tagged “pip” — page 24 · VulnSea