Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-67322High· 7.5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…
MAL-2026-11426NoneMalicious code in trtllm-subdir-test (PyPI)
Malicious code in trtllm-subdir-test (PyPI)
MAL-2026-11425NoneMalicious code in nvtorch-oot-nightly (PyPI)
Malicious code in nvtorch-oot-nightly (PyPI)
MAL-2026-11424NoneMalicious code in telerape (PyPI)
Malicious code in telerape (PyPI)
MAL-2026-11423NoneMalicious code in asdk-plugin-legacy (PyPI)
Malicious code in asdk-plugin-legacy (PyPI)
MAL-2026-11422NoneMalicious code in asdk-plugin-alphagen (PyPI)
Malicious code in asdk-plugin-alphagen (PyPI)
MAL-2026-11421NoneMalicious code in asdk-plugin-ai-platform (PyPI)
Malicious code in asdk-plugin-ai-platform (PyPI)
CVE-2026-54785Medium· 6.2gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining…
CVE-2026-53505High· 7.5Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extreme…
CVE-2026-53502HighThumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or f…
MAL-2026-11420NoneMalicious code in walmart-genai-trace (PyPI)
Malicious code in walmart-genai-trace (PyPI)
MAL-2026-11419NoneMalicious code in cognikit (PyPI)
Malicious code in cognikit (PyPI)
MAL-2026-11418NoneMalicious code in catalogai (PyPI)
Malicious code in catalogai (PyPI)
MAL-2026-11417NoneMalicious code in aiprepkit (PyPI)
Malicious code in aiprepkit (PyPI)
MAL-2026-11416NoneMalicious code in ailaunchkit (PyPI)
Malicious code in ailaunchkit (PyPI)
MAL-2026-11415NoneMalicious code in aichannel (PyPI)
Malicious code in aichannel (PyPI)
MAL-2026-11414NoneMalicious code in aiassistcore (PyPI)
Malicious code in aiassistcore (PyPI)
MAL-2026-11413NoneMalicious code in reguestsc (PyPI)
Malicious code in reguestsc (PyPI)
CVE-2026-53500High· 8.2Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist.…
CVE-2026-53501High· 8.2Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() …
CVE-2026-53503High· 7.5Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filter…
CVE-2026-53504High· 7.5Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing t…
CVE-2026-54707Medium· 5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files sett…
CVE-2026-54706Medium· 4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…
CVE-2026-12074High· 7.5Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12072High· 7.5Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12061High· 7.5Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
CVE-2026-12075High· 8.6Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
CVE-2026-59881Medium· 5.3aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)
A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…
MAL-2026-11202NoneMalicious code in ml-shared (PyPI)
Malicious code in ml-shared (PyPI)