VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-67322High· 7.5
1mo ago

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.33%via NVD
MAL-2026-11426None
1mo ago

Malicious code in trtllm-subdir-test (PyPI)

Malicious code in trtllm-subdir-test (PyPI)

▾ Sunlittrtllm-subdir-test · trtllm-subdir-testvia OSV
MAL-2026-11425None
1mo ago

Malicious code in nvtorch-oot-nightly (PyPI)

Malicious code in nvtorch-oot-nightly (PyPI)

▾ Sunlitnvtorch-oot-nightly · nvtorch-oot-nightlyvia OSV
MAL-2026-11424None
1mo ago

Malicious code in telerape (PyPI)

Malicious code in telerape (PyPI)

▾ Sunlittelerape · telerapevia OSV
MAL-2026-11423None
1mo ago

Malicious code in asdk-plugin-legacy (PyPI)

Malicious code in asdk-plugin-legacy (PyPI)

▾ Sunlitasdk-plugin-legacy · asdk-plugin-legacyvia OSV
MAL-2026-11422None
1mo ago

Malicious code in asdk-plugin-alphagen (PyPI)

Malicious code in asdk-plugin-alphagen (PyPI)

▾ Sunlitasdk-plugin-alphagen · asdk-plugin-alphagenvia OSV
MAL-2026-11421None
1mo ago

Malicious code in asdk-plugin-ai-platform (PyPI)

Malicious code in asdk-plugin-ai-platform (PyPI)

▾ Sunlitasdk-plugin-ai-platform · asdk-plugin-ai-platformvia OSV
CVE-2026-54785Medium· 6.2
1mo ago

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining…

▾ Sunlitgemini-bridge · gemini-bridgeEPSS 0.19%via NVD
CVE-2026-53505High· 7.5
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extreme…

▾ Twilightthumbor · thumborEPSS 0.61%via NVD
CVE-2026-53502High
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or f…

▾ Twilightthumbor · thumborEPSS 0.52%via NVD
MAL-2026-11420None
1mo ago

Malicious code in walmart-genai-trace (PyPI)

Malicious code in walmart-genai-trace (PyPI)

▾ Sunlitwalmart-genai-trace · walmart-genai-tracevia OSV
MAL-2026-11419None
1mo ago

Malicious code in cognikit (PyPI)

Malicious code in cognikit (PyPI)

▾ Sunlitcognikit · cognikitvia OSV
MAL-2026-11418None
1mo ago

Malicious code in catalogai (PyPI)

Malicious code in catalogai (PyPI)

▾ Sunlitcatalogai · catalogaivia OSV
MAL-2026-11417None
1mo ago

Malicious code in aiprepkit (PyPI)

Malicious code in aiprepkit (PyPI)

▾ Sunlitaiprepkit · aiprepkitvia OSV
MAL-2026-11416None
1mo ago

Malicious code in ailaunchkit (PyPI)

Malicious code in ailaunchkit (PyPI)

▾ Sunlitailaunchkit · ailaunchkitvia OSV
MAL-2026-11415None
1mo ago

Malicious code in aichannel (PyPI)

Malicious code in aichannel (PyPI)

▾ Sunlitaichannel · aichannelvia OSV
MAL-2026-11414None
1mo ago

Malicious code in aiassistcore (PyPI)

Malicious code in aiassistcore (PyPI)

▾ Sunlitaiassistcore · aiassistcorevia OSV
MAL-2026-11413None
1mo ago

Malicious code in reguestsc (PyPI)

Malicious code in reguestsc (PyPI)

▾ Sunlitreguestsc · reguestscvia OSV
CVE-2026-53500High· 8.2
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist.…

▾ Twilightthumbor · thumborEPSS 0.50%via NVD
CVE-2026-53501High· 8.2
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() …

▾ Twilightthumbor · thumborEPSS 0.35%via NVD
CVE-2026-53503High· 7.5
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filter…

▾ Twilightthumbor · thumborEPSS 0.75%via NVD
CVE-2026-53504High· 7.5
1mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing t…

▾ Twilightthumbor · thumborEPSS 0.61%via NVD
CVE-2026-54707Medium· 5.4
1mo ago

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files sett…

▾ Sunlitonionshare-cli · onionshare-cliEPSS 0.40%via NVD
CVE-2026-54706Medium· 4.8
1mo ago

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…

▾ Sunlitonionshare-cli · onionshare-cliEPSS 0.34%via NVD
CVE-2026-12074High· 7.5
1mo ago

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-12072High· 7.5
1mo ago

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-12061High· 7.5
1mo ago

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

▾ Twilightnltk · nltkvia OSV
CVE-2026-12075High· 8.6
1mo ago

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

▾ Twilightnltk · nltkvia OSV
CVE-2026-59881Medium· 5.3
2mo ago

aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)

A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
MAL-2026-11202None
2mo ago

Malicious code in ml-shared (PyPI)

Malicious code in ml-shared (PyPI)

▾ Sunlitml-shared · ml-sharedvia OSV
CVEs tagged “pip” — page 26 · VulnSea